HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 1 min ago.
- Webshell in Fake Plugin /blnmrpb/ Directory
Research Sucuri, 27 Jan 2020
Our team recently discovered a web shell attempting to hide within a fake WordPress plugin directory wp-content/plugins/blnmrpb/ . Inside this fake plugin directory were only two files: index.php and log.txt . At first glance, the index....
- Personal Online Security - Account Management
Research Sucuri, 24 Jan 2020
Continuing a series on how to better strengthen your personal online privacy, we are looking to take personal inventory of how we connect online. These were themes covered during our webinar “Security Beyond Your Website: Personal Online...
- Backdoor Found in Compromised WordPress Environment
Research Sucuri, 23 Jan 2020
Our security analyst Ben Martin recently came across a backdoor in a compromised WordPress installation that had been injected into the first line of the theme file ./wp-content/themes/flatsome/ header.php . if(isset($_POST[chr(97).chr(1...
- Fake AmeriCommerce Shopping Cart
Research Sucuri, 23 Jan 2020
Our malware analyst Liam Smith recently found malware on a client’s site that targets ecommerce sites powered by AmeriCommerce software. A popular ecommerce software solution that allows users to run multiple carts with a single admin us...
- Malicious JavaScript Used in WP Site/Home URL Redirects
Research Sucuri, 21 Jan 2020
Our team recently found a malicious JavaScript injection within the WordPress index.php theme file on a compromised WordPress website which ultimately redirects site visitors to a survey-for-gifts scam website. At this time of writing, w...
- Simple WAF Evasion Backdoor
Research Sucuri, 17 Jan 2020
Our team recently located a malicious PHP file on a compromised website which claims to evade web application firewalls, with the intention of downloading a malicious script to a compromised web-server. $a = "\x66\x69\x6c\x65\x5f\x67\x65...
- Zen Cart “PayPal” Skimmer
Research Sucuri, 17 Jan 2020
While we mostly see skimmers on Magento based websites, this does not mean that less-popular ecommerce platforms are safe from infections with similar payment information stealing malware. Our security analyst Christopher Morrow recently...
- Authentication Bypass Vulnerability in InfiniteWP Client
Research Sucuri, 16 Jan 2020
An authentication bypass vulnerability affecting more than 300,000 InfiniteWP Client plugin users has recently been disclosed to the public. This plugin allows site owners to manage multiple websites from one central server using the Inf...
- Magento Skimmer Found Loading from magecart[.]net
Research Sucuri, 16 Jan 2020
We recently came across a simple Magento credit card skimmer found on a compromised website that was loading from the malicious domain magecart[.]net. The malicious domain was first registered on December 8th, 2019 and is likely a blatan...
- WordPress Mass Password Changer
Research Sucuri, 14 Jan 2020
Our team recently came across a password changer for WordPress that allows attackers to modify WordPress user passwords within a compromised environment. By default, the tool is set to target user ID=1 , which is almost always the admini...
- Critical Vulnerability In InfiniteWP Client And WP Time Capsule
Research Patchstack, 14 Jan 2020
Not too long ago an authentication bypass vulnerability in the Ultimate Addons was found for Elementor and Beaver Builder plugins. As we routinely monitor the code of popular plugins our customers use, we found that the InfiniteWP Client...
- The Anatomy of Website Malware Part 2: Credit Card Stealers
Research Sucuri, 30 Dec 2019
One of the biggest malicious trends in the last few months and years are credit card stealers - also commonly referred to as credit card skimmers or cc stealers. In the second part of this Website Malware Anatomy series, I’m going to dec...
- How Passwords Get Hacked
Research Sucuri, 26 Dec 2019
How many passwords do you use in a given day? Everything on the internet requires a password. It can be tough to keep track of them all and keep coming up with strong passwords. For proof, listen to the grumblings in most office building...
- 5 Year Anniversary of the SoakSoak Malware Tsunami
Research Sucuri, 19 Dec 2019
This is a story about the SoakSoak malware campaign that proved that you can’t underestimate impact of security issues in popular premium software. These days, the majority of popular content management systems are 100% free: WordPress, ...
- How Websites Are Used to Spread Emotet Malware
Research Sucuri, 18 Dec 2019
In past posts, we’ve discussed the more popular reasons why hackers target smaller websites. Today, we’ll focus instead on how hackers use compromised websites to spread dangerous malware like Emotet to end user victims. Emotet Threat Fi...
- 5 Malware & Virus Scanning Tools You Need to Check Out
Research Sucuri, 16 Dec 2019
Website malware is no joke. Our own research shows that with WordPress, by far today’s most common content management system (CMS), new infections are on the rise. Even with security researchers working constantly to uncover and remediat...
- Unmasking Black Hat SEO for Dating Scams
Research Sucuri, 12 Dec 2019
Malware obfuscation comes in all shapes and sizes - and it’s sometimes hard to recognize the difference between malicious and legitimate code when you see it. Recently, we came across an interesting case where attackers went a few extra ...
- Why Hackers Create Phishing Campaigns
Research Sucuri, 9 Dec 2019
Phishing is a malicious attempt to obtain personally identifiable information of a victim. The first thing to keep in mind about phishing is the goal of the attackers. In the first post of this series, we have explained how to recognize ...
- Personal Online Privacy - Data & Browser Privacy
Research Sucuri, 6 Dec 2019
Continuing a series on how to strengthen your personal online privacy, we are taking personal inventory of how we connect online. These were themes covered during our webinar on “Security Beyond Your Website: Personal Online Privacy” and...
- Plugins added to Malware Campaign: November 2019
Research Sucuri, 2 Dec 2019
This is an update for the long-lasting malware campaign targeting vulnerable plugins since January. Please check our previous updates below: Multi-Vector Attack in Server Logs: March 2019 Plugins Added to Malicious Campaign - April 2019 ...
- Another Fake Google Domain: fonts.googlesapi.com
Research Sucuri, 2 Dec 2019
Our Remediation team lead Ben Martin recently found a fake Google domain that is pretty convincing to the naked eye. The malicious domain was abusing the URL shortener service is.gd : shortened URLs were being injected into the posts tab...
- Wrong content-type to XSS
Research Sucuri, 22 Nov 2019
WordPress Social Sharing Plugin - Sassy Social Share, which currently has over 100000 installations just fixed a Cross Site Scripting Vulnerability. This bug allows attackers to send custom links that direct unsuspecting users toward a v...
- How Many Types of Hackers Are There?
Research Sucuri, 22 Nov 2019
If you are a tech savvy person, you may have been called a “hacker” at some point by someone less technical. Maybe you’ve heard of growth hackers and life hacks. These are not the droids we’re looking for. The word “hack” in computer sys...
- Down the Malware Rabbit Hole: Part II
Research Sucuri, 18 Nov 2019
In our last post in this series, we took a look at a code snippet that had been encoded in a very specific way - and hidden 91 layers deep. Today, we’ll reveal how attackers achieve this level of encoding and investigate one of the many ...
- Why Reinfections Happen with a WAF
Research Sucuri, 11 Nov 2019
A web application firewall ( WAF ) is a great way to detect and filter incoming malicious requests before they can exploit website vulnerabilities and security flaws. While a WAF helps protect against threats over HTTP/HTTPS, the website...
- Vulnerable Versions of Adminer as a Universal Infection Vector
Research Sucuri, 9 Nov 2019
This past week, we’ve been monitoring a new wave of website infections mostly impacting WordPress and Magento websites. We found that hackers have been injecting scripts from scripts.trasnaltemyrecords[.]com into multiple files and datab...
- Skimmers for Both Magento and WordPress
Research Sucuri, 7 Nov 2019
We often write about malware that steal payment information from sites built with Magento and other types of e-commerce CMS. When discussing credit card skimmers like Magecart, it’s sometimes overlooked that WordPress also has a decent s...
- Plugins added to Malware Campaign: October 2019
Research Sucuri, 6 Nov 2019
This is an update for the long-lasting malware campaign targeting vulnerable plugins during August and September. Please check our previous updates below: Multi-Vector Attack in Server Logs: March 2019 Plugins Added to Malicious Campaign...
- Size for Opera: Hiding Spammy Links
Research Sucuri, 5 Nov 2019
There are many different tricks hackers use to make injected spam links invisible to regular visitors. Below is an example employed by one link spam campaign, which primarily promotes porn, torrents, and pharma. We’re finding links like ...
- Pharma Spam Redirects to .su & .eu Sites
Research Sucuri, 4 Nov 2019
We regularly clean all sorts of black hat SEO infections. During these infection cleanups, we often find compromised websites redirecting visitors to fake “Canadian Pharmacy” landing pages selling counterfeit men’s health pills from vari...
- Halloween Tales of the IoT Crypt
Research Sucuri, 31 Oct 2019
In the spirit of Halloween, we bring you some of the scariest internet of things (IoT) hacks that we have been made aware of. While this does not really focus on website security, it is still an interesting topic when you think about cyb...
- Data URLs and HTML Entities in New WordPress Malware
Research Sucuri, 30 Oct 2019
Last week, an ongoing WordPress malware campaign started a new wave which included a variety of experimental injection types. Scripts as Data URLs The first type looks pretty similar to what we discussed in our recent post. However, inst...
- Fake French Police Sextortion Scam
Research Sucuri, 28 Oct 2019
There has been a noted increase in the number of sextortion scams during 2019. These scam campaigns are commonly distributed through email, but any method of digital communication can be used to deliver the blackmail threat to the victim...
- Throwback Threat Thursday: JCE Vulnerability
Research Sucuri, 24 Oct 2019
Throwback Threat Thursday is a series of posts where we recall older vulnerabilities that have since been patched by their developers. In the past, these vulnerabilities caused significant impacts to the security of website owners. Some ...
- Fake UpdraftPlus Plugins
Research Sucuri, 17 Oct 2019
We often find various fake WordPress plugins installed by hackers during website cleanups. Recently, we’ve noticed a new wave of infections that install fake plugins with backdoor functionality. Malicious Plugins Sourced from UpdraftPlus...
- Sucuri_encrypted: Magento Malware
Research Sucuri, 17 Oct 2019
In an effort to make malicious code appear to be credible, hackers commonly piggyback on the names of reputable, well-known companies and services. Typical examples of this technique include malware campaigns that abuse names of jQuery a...
- Cryptominers & Backdoors Found in Fake Plugins
Research Sucuri, 16 Oct 2019
When cleaning websites, we regularly find phishing pages, malicious code injected into files, and SEO spam. However, over the past couple of months we’ve also noticed a considerable increase in the number of malicious plugins which have ...
- What Are Ethical Hackers?
Research Sucuri, 11 Oct 2019
There’s an issue with how some people define the word “hacker.” For some, it’s a word synonymous with “cybercriminal,” but not in the infosec community. White hat hackers (the good guys) are the ones who find security issues so they can ...
- What is the Cost of Cybercrimes & Attacks
Research Sucuri, 7 Oct 2019
The word cybercrime is no longer just a word you hear coming from Fortune 500 CEOs anymore. This word has being flashed on every good morning news show and radio channel. Cybercrime can target any business or website owner. Even the aver...
- Plugins added to Malware Campaign: September 2019
Research Sucuri, 3 Oct 2019
This is an update for the long-lasting malware campaign targeting vulnerable plugins during August and September. Please check our previous updates below: Multi-Vector Attack in Server Logs: March 2019 Malware Campaign Evolves to Target ...
- Down the Malware Rabbit Hole - Part 1
Research Sucuri, 3 Oct 2019
It’s common for malware to be encoded to hide itself-or its true intentions-but have you ever given thought to what lengths attackers will go to hide their malicious code? In our first post in this series, we’ll describe how bad actors h...
- A New Wave of Buggy WordPress Infections
Research Sucuri, 2 Oct 2019
We’ve been following an ongoing malware campaign for the past couple of years now. This campaign is renowned for its prompt addition of exploits for newly discovered WordPress theme and plugin vulnerabilities. Every other week, the attac...
- The Hacker Returns: A Backdoor Edition
Research Sucuri, 24 Sep 2019
Once an attacker manages to hack and gain access to a target site or system, they typically work hard to maintain their access-as long as it can to help them achieve their goals. You can think of it like having an annoying party-crasher ...
- Plugins Under Attack: August 2019
Research Sucuri, 19 Sep 2019
This is an update for the long-lasting malware campaign targeting vulnerable plugins during August and September. Please check our previous updates below: Multi-Vector Attack in Server Logs: March 2019 Malware Campaign Evolves to Target ...
- Fake Human Verification Spam
Research Sucuri, 18 Sep 2019
We recently released an update to our Labs Knowledgebase for new plugins that had been targeted during the month of July 2019. One of these newly targeted plugins was Advanced Booking Calendar - and it didn’t take long before we were rec...
- Unauthenticated settings update in woocommerce-ajax-filters
Research Sucuri, 18 Sep 2019
woocommerce-ajax-filters, which currently has over 10,000 installations (versions admin_init hook’s execution context. if( is_admin() ) { require_once dirname( __FILE__ ) . '/includes/wizard.php'; } [...] function wizard_selectors($wizar...
- Misuse of WordPress update_option() function Leads to Website Infections
Research Sucuri, 16 Sep 2019
In the past four months, Sucuri has seen an increase in the number of plugins affected by the misuse of WordPress’ update_option() function. This function is used to update a named option/value in the options database table. If developer...
- Dissecting the WordPress 5.2.3 Update
Research Sucuri, 13 Sep 2019
Last week, WordPress released version 5.2.3 which was a security and maintenance update, and as such, contained many security fixes. Part of our day to day work is to analyse these security releases, discover what security issue it is fi...
- How to Audit & Cleanup WordPress Plugins & Themes
Research Sucuri, 9 Sep 2019
WordPress makes it easy to extend your website with powerful functionality. Plugins and themes allow site owners to add features, customize design, and integrate new tools in minutes. But every new add-on also introduces new code and new...
- Throwback Threat Thursday: Joomla GoogleMaps Plugin SEO Spam Injection
Research Sucuri, 5 Sep 2019
Throwback Threat Thursday is a series of posts where we recall older vulnerabilities that have since been patched by their developers. In the past, these vulnerabilities caused significant impacts to the security of website owners. Some ...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.