Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,878 reports kept since 2009. Updated automatically every 10 minutes. Last checked 2 min ago.

  1. What is FTP? Why use it to clean hacked websites?

    Research Sucuri, 18 May 2020

    The File Transfer Protocol (FTP) is a network protocol used to transfer files between a client server and a network. In other words, it is through FTP that we get text and images onto a website. Why is FTP used to clean up a website? Not...

  2. WordPress Malware Collects Sensitive WooCommerce Data

    Research Sucuri, 15 May 2020

    During a recent investigation, our team found malicious code that reveals how attackers are performing reconnaissance to identify if sites are actively using WooCommerce in a compromised hosting environment. These compromised websites ar...

  3. Unauthenticated Stored Cross Site Scripting in WP Product Review

    Research Sucuri, 14 May 2020

    During a routine research audit for our Sucuri Firewall , we discovered an Unauthenticated Persistent Cross-Site Scripting (XSS) affecting 40,000+ users of the WP Product Review plugin. Current State of the Vulnerability Though this secu...

  4. B374k Web Shell Packer

    Research Sucuri, 13 May 2020

    PHP web shells are a type of backdoor which, when left on compromised websites, allow attackers to maintain unauthorized access after initial compromise. To further evade detection, attackers may also choose to keep a packer script on a ...

  5. YouTube Account Recovery Phishing

    Research Sucuri, 12 May 2020

    Phishing attacks against targeted channels have been successful in the past, as explained last year on ZDNet. Recently, our Remediation team found an interesting phishing page following a similar pattern that was targeting YouTube creato...

  6. Elementor PRO Vulnerability And Attack Analysis

    Research Patchstack, 8 May 2020

    This article analyses the Elementor PRO Vulnerability vulnerabilities. Elementor PRO is a page builder for WordPress with approximately 1+ million users. On the 4th of May, many websites had a suspicious subscriber registering to the sit...

  7. Labs Notes Monthly Recap - April/2020

    Research Sucuri, 4 May 2020

    In 2020, we doubled up our research efforts to report on many new attacks and hacks that we see in the wild. We believe that being informed is a big part of having a good website security posture. Sucuri Labs provides website malware res...

  8. Vulnerabilities Digest: April 2020

    Research Sucuri, 1 May 2020

    Relevant Plugins and Vulnerabilities: Plugin Vulnerability Patched Version Installs Widget Settings Importer/Exporter Stored XSS Closed 40000 Accordion Stored/Reflected XSS 2.2.9 30000 Support Ticket System By Phoeniixx Reflected XSS Clo...

  9. WordPress Admin Login Stealer

    Research Sucuri, 27 Apr 2020

    During an investigation, we identified a WordPress login stealer using the PHP functions curl and file_get_contents . The malicious code was injected into the core file wp-login.php to intercept the information of a valid user and send i...

  10. Duplicated Vulnerabilities in WordPress Plugins

    Research Sucuri, 24 Apr 2020

    During a recent plugin audit, we noticed a weird pattern among many plugins responsible for performing a specific task: Duplicating a page or a post. With a bit of research, we came to the following conclusion: Many of these plugins came...

  11. Web Skimmer With a Domain Name Generator - Follow Up

    Research Sucuri, 23 Apr 2020

    This note is a follow up to our recent post about a web skimmer that uses a dynamic domain name generating algorithm. This week, analyst Ben Martin found another variation of the same malware. The script looks very similar. The changes h...

  12. PinnacleCart Server-Side Skimmers and Backdoors

    Research Sucuri, 22 Apr 2020

    While open-source ecommerce platforms are the most common targets for web skimmers, hackers also target paid-for software - especially if it’s used on high-profile online stores with large user-bases. This time, our analysts Kara Federow...

  13. Fake M-Shield WordPress Plugin

    Research Sucuri, 21 Apr 2020

    During a recent malware investigation, we found a fake WordPress plugin called M-Shield . We also found almost an identical plugin under the name kingof , with malicious code hosted in the file: ./wp-content/plugins/kingof/kingof.php Bas...

  14. Obfuscated WordPress Malware Dropper

    Research Sucuri, 21 Apr 2020

    It goes without saying that evasive maneuvering is at the top of a hacker’s priority list. Most often, they try to evade detection by obfuscating their malicious code to make it unreadable to the naked eye. In our recent post we demonstr...

  15. Magento JavaScript Skimmer Targets Tarjetas de Crédito

    Research Sucuri, 17 Apr 2020

    A website owner recently contacted us regarding a payment problem on their Magento website. A suspicious payment card form was loading for customers who were trying to pay for items in their shopping cart: This payment card form should N...

  16. Web Skimmer with a Domain Name Generator

    Research Sucuri, 17 Apr 2020

    Our security analyst Moe Obaid recently found yet another variation of a web skimmer script injected into a Magento database. The malicious script loads the credit card stealing code from qr201346[.]pw and sends the stolen details to hxx...

  17. OneTone Vulnerability Leads to JavaScript Cookie Hijacking

    Research Sucuri, 15 Apr 2020

    A vulnerability in the discontinued WordPress theme OneTone has been added to an ongoing campaign that is targeting vulnerable WordPress websites and causes malicious redirects through domains like ischeck [ . ] xyz . This specific wave ...

  18. Analysis of a WordPress Credit Card Swiper

    Research Sucuri, 9 Apr 2020

    While working on a recent case, I found something on a WordPress website that is not as common as on Magento environments: A credit card swiper injection. Typically this type of malware targets dedicated ecommerce platforms such as Magen...

  19. Spl_autoload Backdoor

    Research Sucuri, 8 Apr 2020

    With backdoors, one of the main challenges for malware authors is to execute code without using obvious functions (such as eval , asset , create_function , etc.) that trigger alerts for security scanners. In the following example found b...

  20. Top 10 Hacks & Attacks from 2019

    Research Sucuri, 8 Apr 2020

    Last year was a busy one in the world of website security. Our 2019 Threat Research Report shows that over 60% of websites we cleaned had a vulnerability at the point of infection, up 4% over 2018. SEO spam remained a universal threat, w...

  21. Fake License.txt File Loaded Through PHP Include

    Research Sucuri, 3 Apr 2020

    Our team recently found a malicious injection located within a PHP include. The redirect occurs via the include function, which includes a file inconspicuously named license.txt . During our investigation, we located the license.txt inje...

  22. Face Mask Spam Links Injected in WordPress Database

    Research Sucuri, 2 Apr 2020

    During a recent malware removal request, we found a compromised WordPress site being used to redirect to spam websites. The campaign was leveraging an increase in search queries related to face masks . To make their campaign more difficu...

  23. How to Find & Fix the Japanese Keyword Hack

    Research Sucuri, 2 Apr 2020

    If you’re wondering how to find and fix the Japanese keyword hack, get started by identifying a real-life example. First, open Google Translate, and then get the Japanese characters for the search term buy Ralph Lauren . Copy and paste t...

  24. Vulnerabilities Digest: March 2020

    Research Sucuri, 27 Mar 2020

    Fixed Plugins and Vulnerabilities Plugin Vulnerability Patched Version Installs Cookiebot Reflected Cross-Site Scripting 3.6.1 40000 Data Tables Generator By Supsystic Authenticated Stored XSS 1.9.92 30000 WPvivid Backup Database Leak 0....

  25. Tiny WSO Webshell Loader

    Research Sucuri, 24 Mar 2020

    A PHP webshell is a common tool found on compromised environments. Attackers use webshells as backdoors, allowing them to maintain unauthorized access to a hacked website. Bad actors can also use webshells to perform various functions wi...

  26. Safe Browsing During a Pandemic: How to Spot COVID-19 Phishing Campaigns

    Research Sucuri, 23 Mar 2020

    Online bad actors tend to take advantage of tragedy for their own gain - and the coronavirus is no different. While we would hope that cybercriminals would be sympathetic during a global health crisis, it already appears this may be a pi...

  27. Reflected XSS in Cookiebot Administrative Page

    Research Sucuri, 23 Mar 2020

    A reflected XSS vulnerability has recently been found in the Cookiebot plugin plugin, impacting a user base of over 40k installs. Versions prior to 3.6.1 are susceptible to this attack, which allows hackers to exploit the vulnerability f...

  28. Extract Function Backdoor Variant

    Research Sucuri, 18 Mar 2020

    We recently found malware on a client’s WordPress site that was using a variant of a backdoor that we previously covered back in 2014. The primary difference in this backdoor is that the malware has been formatted so that it is easier to...

  29. Reflected XSS in Advanced Ads Admin Dashboard

    Research Sucuri, 17 Mar 2020

    A patch for a vulnerability in the Advanced Ads plugin has been released. Prior to version 1.17.4 , attackers were able to exploit two reflected XSS attacks via the admin dashboard. Both vulnerabilities are related to the advads-last-edi...

  30. Innocent Defacement

    Research Sucuri, 13 Mar 2020

    When we talk about defacements, we’re usually referring to attacks leading to a visual takeover of a website’s page ― consider it a form of vandalism or graffiti. Often distributed by hacktivists via political motivation, defacements usu...

  31. Throwback Threat Thursday: WordPress 4.7 WP-JSON Content Injection Vulnerability

    Research Sucuri, 12 Mar 2020

    Throwback Threat Thursday is a series of posts where we recall older vulnerabilities that have since been patched by their developers. In the past, these vulnerabilities caused significant impacts to the security of website owners. Some ...

  32. WordPress Database Brute Force and Backdoors

    Research Sucuri, 11 Mar 2020

    We regularly talk about brute force attacks on WordPress sites and explain why WordPress credentials should always be unique, complex, and hard to guess. However, the WordPress login is not the only point of entry that hackers use to bre...

  33. Phishing and Malware via SMS Text Message

    Research Sucuri, 6 Mar 2020

    We’ve recently noticed an increase in reports of phishing and malware being distributed via SMS text messages. During one investigation, we identified fake messages sent from a random number pretending to be Amazon. The message contents ...

  34. Vulnerabilities Digest: February 2020

    Research Sucuri, 2 Mar 2020

    Fixed Plugins and Vulnerabilities Plugin Vulnerability Patched Version Installs Duplicator Arbitrary File Download 1.3.28 1000000 Modula Image Gallery Authenticated Stored XSS 2.2.5 70000 Easy Property Listings CSRF 3.4 6000 ThemeREX Add...

  35. What is Pharma Hack Spam?

    Research Sucuri, 27 Feb 2020

    Have you ever seen a website advertising products that seem unrelated to the apparent purpose of the site? Often, this suspicious content is promising pharmacy drugs, available quickly and without a prescription. That’s a classic example...

  36. Skimmer Plugin Hides Itself From wp-admin

    Research Sucuri, 27 Feb 2020

    Our analyst Moe O recently discovered an interesting Javascript injection that was stealing submitted payment data from visitors on a WordPress website with a Woocommerce storefront. The Javascript was found to be loading from a maliciou...

  37. Malicious WordPress User Hijacker

    Research Sucuri, 25 Feb 2020

    Our analyst Liam Smith recently found a malicious file with the name wp-atom2.php on a compromised WordPress site that had been infected with pharma spam. The spam content had been found injected into the _postmeta table within the WordP...

  38. Website Vulnerability vs. Malware - What’s the Difference?

    Research Sucuri, 24 Feb 2020

    To better understand the difference between website malware and vulnerabilities, imagine your online property is a brick-and-mortar structure. You’d want to keep safe from burglars, so you take measures to protect your house, like locked...

  39. How to Find & Remove SEO Spam on WordPress

    Research Sucuri, 20 Feb 2020

    Perhaps the best way to dive into the subject of finding and removing SEO spam on WordPress is with a quick experiment - probably one you’ll want to conduct at a private location. Run a Google search with the terms buy viagra cialis . Wi...

  40. Is My Site Hacked? (7 Signs)

    Research Sucuri, 19 Feb 2020

    Editorial: This post was last updated October 26th, 2022. It’s a day every website owner fears. You open the website you’ve poured your time, energy, and money into, only to find your home page looking very different. After your stomach ...

  41. Critical Issue In ThemeGrill Demo Importer

    Research Patchstack, 16 Feb 2020

    The ThemeGrill Demo Importer plugin has 200,000+ active installations and can be used to import ThemeGrill official themes demo content, widgets, and theme settings with just one click. Update (18th of February):The installs count has dr...

  42. What is Ransomware?

    Research Sucuri, 12 Feb 2020

    Originally published: February 12, 2020 by Justin Channell Ransomware has been one of the scariest topics in cybersecurity for years - and for good reason. Living up to its name, ransomware is a type of malware where a bad actor blocks a...

  43. 6 Simple Steps for Hardening your WordPress Security

    Research Sucuri, 5 Feb 2020

    Having a secure WordPress site does not need to be a challenge. Hardening a website means adding security layers to reduce the risks of attacks and hacks. 6 ways to Harden WordPress Security You can harden your WordPress site by followin...

  44. Email Scraper: Mass Mail Grabber from Database

    Research Sucuri, 5 Feb 2020

    One of our Remediation team analysts, Liam Smith, discovered a malicious file on a client’s compromised WordPress website that demonstrates how attackers can use rudimentary tools to extract specific data from available databases. In thi...

  45. PHP Dropper Concealed in Malicious WordPress Plugin

    Research Sucuri, 30 Jan 2020

    Moe Obaid - an analyst from our Remediation Team - recently found a PHP dropper that had been installed as a malicious WordPress plugin. Unlike other fake plugins we’ve recently written about, this plugin had been installed and activated...

  46. Stored XSS in Elementor

    Research Sucuri, 29 Jan 2020

    During a routine audit of WordPress plugins last december, we discovered a Stored XSS vulnerability in the very popular Elementor Page Builder plugin, which powers no less than 3 million+ websites according to the official active install...

  47. Vulnerabilities Digest: January 2020

    Research Sucuri, 28 Jan 2020

    Fixed Plugins and Vulnerabilities Plugin Vulnerability Patched Version Installs InfiniteWP Client Login bypass 1.9.4.5 300000 ListingPro Reflected XSS 2.5.4 13000 Travel Booking Stored XSS 2.7.8.6 7627 Real Estate 7 Stored XSS 2.9.5 7725...

  48. Hacked Website Threat Report - 2019

    Research Sucuri, 28 Jan 2020

    The threat landscape for website owners is constantly shifting on a regular basis - and it’s becoming increasingly more complex. As attackers continue to develop tools and find new vulnerabilities to massively exploit, our team works dil...

  49. Web Swiper in Image Title

    Research Sucuri, 27 Jan 2020

    Cybercriminals regularly try a variety of approaches to hide their malicious code - web skimmers are well known for using all sorts of obfuscation and masquerading. Suspicious Img Tag Our malware analyst Liam Smith recently discovered a ...

  50. Webshell in Fake Plugin /blnmrpb/ Directory

    Research Sucuri, 27 Jan 2020

    Our team recently discovered a web shell attempting to hide within a fake WordPress plugin directory wp-content/plugins/blnmrpb/ . Inside this fake plugin directory were only two files: index.php and log.txt . At first glance, the index....

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support