HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 7 min ago.
- What is Cryptocurrency Mining Malware?
Research Sucuri, 2 Sep 2019
Before we get into the details of “Cryptocurrency Mining Malware”, we need to understand first what cryptocurrency is and what miners are. What is Cryptocurrency? Cryptocurrency is best thought of as digital currency and it only exists o...
- TimThumb Attacks: The Scale of Legacy Malware Infections
Research Sucuri, 29 Aug 2019
These days, we consider a malware campaign massive if it affects a couple thousand websites. However, back in the day when Sucuri first started its operations, the scale of infections was significantly larger - and it was quite typical t...
- How Domain Expiration Can Potentially Disrupt Other Websites
Research Sucuri, 22 Aug 2019
A website owner recently reached out to us about a pop-up advertisement problem on their website which occurred any time someone clicked anywhere on the web page. This irritating pop-up didn’t come from malware placed in the website’s fi...
- Lack of controls when using WordPress’ update_option() with user input data equals plugin nightmare
Research Sucuri, 20 Aug 2019
As mentioned in recent posts, WordPress’ update_option() function is used to update any option in the options database table. If the permission flow when using this function isn’t correctly implemented by developers, attackers can gain a...
- What Hackers Do after Gaining Access to a Website
Research Sucuri, 15 Aug 2019
A hack or cyber attack is the act of maliciously entering, taking control over, or manipulating by force a web application, server, or file that belongs to someone else. Cyber attacks will: modify files, retrieve information, insert comm...
- Skimmers and Phishing
Research Sucuri, 14 Aug 2019
Recently, we shared a post about a network of domains used in a JavaScript credit card stealing malware campaign. These domains are all hosted on the same server with the IP 8.208.15.67 . In addition to the domains used by the skimmers, ...
- Troldesh Ransomware Dropper
Research Sucuri, 12 Aug 2019
Over the past few weeks, we’ve seen an increase in Troldesh ransomware using compromised websites as intermediary malware distributors. The malware often uses a PHP file that acts as a delivery tool for downloading the host malware dropp...
- KOSONG Credit Card Stealer
Research Sucuri, 12 Aug 2019
Our security analyst Christopher Morrow recently discovered a server-side Magento skimmer that was injected into the savePayment function in the app/code/core/Mage/Checkout/Model/Type/Onepage.php file. This code emails payment details to...
- Magento Skimmers: From Atob to Alibaba
Research Sucuri, 7 Aug 2019
Last year we saw a fairly massive Magento malware campaign that injected credit card stealing code similar to this: It uses the JavaScript atob function to decode base64-encoded domain names and URL patterns. In the sample above, it’s hx...
- Autoloaded Server-Side Swiper
Research Sucuri, 6 Aug 2019
Front-end JavaScript-based credit card stealing malware has garnered a lot of attention within the security community. This makes sense, since the “swipers” can be easily detected by simply scanning the web pages of e-commerce sites. How...
- User adder backdoor
Research Sucuri, 5 Aug 2019
As we’ve seen many times before, there are a variety of backdoors that can be planted on a website. Post-compromise, it’s almost mandatory to review the list of users with admin capabilities within the website. But, what if you check the...
- Malicious Plugin Used to Encrypt WordPress Posts
Research Sucuri, 5 Aug 2019
During a recent cleanup, we found an interesting malicious WordPress plugin, “WP Security”, that was being used to encrypt blog post content. The website owner complained of a newly installed and activated plugin on their website that wa...
- EE wireless provider phishing malware
Research Sucuri, 1 Aug 2019
A large number of phishing targets include popular services such as banks, payment providers, and email services. In this type of attack, fraudsters create fake pages that appear to be legitimate content, but instead trick victims into d...
- Neapolitan Backdoor Injection
Research Sucuri, 1 Aug 2019
Most of us are familiar with Neapolitan ice cream: a flavour whose distinguishing characteristic is not one single flavour but several. Many also know it as the ice cream which your roommate eats all of the chocolate, leaving you with th...
- New variant of “trollherten” malware
Research Sucuri, 31 Jul 2019
We continue to see new variations of obfuscation used to hide a PHP backdoor that began to be heavily used by malicious users in late 2018 - as we mentioned in a blog post at the time. This variant tries to hide by compressing and encodi...
- Self-destruct malware
Research Sucuri, 31 Jul 2019
The majority of malware we find on compromised websites have been planted by bad actors with the intention of concealing and accessing backdoor access. During a recent investigation, we found an interesting variation of this technique. T...
- Reverse Hardening WordPress Config
Research Sucuri, 30 Jul 2019
Hardening is the process of securing a website or system against known security weaknesses or potential issues to reduce the attack surface. The more functions or features a website has, the more potential points of entry an attacker has...
- Yet another variant of the cPanel user shadow editor malware
Research Sucuri, 30 Jul 2019
We have discovered a new variant of PHP malware used to edit a cPanel users’s shadow file, allowing for bad actors to change passwords for all of the email accounts under that cPanel user. In our past blog post, we analyzed this file’s a...
- Plugins Under Attack: July 2019
Research Sucuri, 29 Jul 2019
A long-lasting malware campaign targeting deprecated, vulnerable versions of plugins continues to be leveraged by attackers to inject malicious scripts into affected websites: Multi-Vector Attack in Server Logs: March 2019 Malware Campai...
- Simple but effective backdoor
Research Sucuri, 29 Jul 2019
We recently found a malicious PHP file containing a small amount of code that is effective at hiding from detection by various server side scanning tools. $a = "\x66\x69\x6c\x65\x5f\x67\x65\x74\x5f\x63\x6f\x6e\x74\x65\x6e\x74\x73"; $b = ...
- Simple WP login stealer
Research Sucuri, 28 Jul 2019
We recently found the following malicious code injected into wp-login.php on multiple compromised websites. \ } // End of login_header() $username_password=$_POST['log']."----xxxxx----".$_POST['pwd']."ip:".$_SERVER['REMOTE_ADDR'].$time =...
- “Loader for Secured Files” and arrayed b374k shell encoding
Research Sucuri, 27 Jul 2019
This file ( 33×77.php ) was detected in the document root of a website during a website cleanup for a client. It demonstrates how hackers sometimes use comments or other text within malicious code to confuse website owners and prevent de...
- Fake Google Domains Used in Evasive Magento Skimmer
Research Sucuri, 25 Jul 2019
We were recently contacted by a Magento website owner who had been blacklisted and was experiencing McAfee SiteAdvisor “Dangerous Site” warnings. Our investigation revealed that the site had been infected with a credit card skimmer loadi...
- How to Perform a Website Security Audit (with Checklist)
Research Sucuri, 24 Jul 2019
Why Should You Audit Your Website for Security? Most hacks and cyber attacks happen because of poor security practices. The first step you can take to improve your online security is knowing exactly what’s installed on your website. Havi...
- Shoesinfy Spam Injections
Research Sucuri, 24 Jul 2019
Lately, we’ve seen quite a few sites with injected spammy links that follow this format: www.shoesfindoutlet[.]co stepper motor The spammy domains may change from time to time but the entire format - and trick to make the content invisib...
- Backdoor plugin hides from view
Research Sucuri, 24 Jul 2019
One of the most important traits for backdoors is the ability to remain undetected by most users - otherwise it may draw suspicion and be deleted, revoking access for bad actors in the process. In the past, we’ve posted about how malicio...
- FBCMS Pharmacy Spam Website
Research Sucuri, 23 Jul 2019
Whenever most people think of a website CMS, they most often think of the popular options like WordPress, Joomla, or Drupal. What do all three of those CMS platforms have in common along with most common CMS platforms? They use a program...
- The Cost of a Hacked Website - Survey
Research Sucuri, 16 Jul 2019
As part of our commitment to the website security community, we want to know the true impacts of a website compromise from the owner’s perspective. If you are a business that has dealt with any type of website attack, your participation ...
- WPTF Hybrid Composer - Unauthenticated Arbitrary Options Update
Research Sucuri, 11 Jul 2019
With almost 300 installs, WPTF - Hybrid Composer is a framework that helps users easily create custom themes for WordPress. We recently noticed an increase in suspicious requests, revealing an attack against this plugin. Easily automated...
- Icegram Persistent Cross-Site Scripting
Research Sucuri, 9 Jul 2019
Icegram is a plugin that helps you collect email addresses for your newsletter. Other features include light-box popup offers, header action bars, toast notifications, and slide-in messengers. Versions 1.10.28.2 and lower are affected by...
- 7 Things You Should Monitor in WordPress Activity Logs
Research Sucuri, 8 Jul 2019
WordPress activity logs can be helpful when troubleshooting or trying to identify a hack. In this article, you’ll learn about the seven things you should monitor in your WordPress logs. Over the years, WordPress has grown more complex. W...
- Spam That Fits Your Website
Research Sucuri, 5 Jul 2019
Most of the time when we talk about spam, we think about mindless machines that create posts or comments to advertise a business related to drugs, accessories, or essays. But what if a hacker tried to convince your clients to click on ma...
- WordPress Plugin WP Statistics: Unauthenticated Stored XSS Under Certain Configurations
Research Sucuri, 3 Jul 2019
The WordPress plugin WP Statistics, which has an active installation base of 500k users, has an unauthenticated stored XSS vulnerability on versions prior to 12.6.7 . This vulnerability can only be exploited under certain configurations-...
- Massive 1800ForBail WordPress Hacks
Research Sucuri, 28 Jun 2019
Sucuri malware analyst Kaushal Bhavsar recently brought our attention to a massive campaign responsible for adding either “ 1800ForBail ” or “ 1800ForBail - One+Number ” keywords to the titles of vulnerable WordPress sites. 1800ForBail i...
- Plugins Under Attack: June 2019
Research Sucuri, 28 Jun 2019
A long-lasting malware campaign (1,2) targeting deprecated, vulnerable versions of plugins continues to be leveraged by attackers to inject malicious scripts into affected websites. As part of a strategy to rotate attack vectors and comp...
- web.config Redirect Malware
Research Sucuri, 26 Jun 2019
We recently found this malware on a windows hosting server where the web.config file was modified with the following code. The code redirects multiple user agents and users referred from Google,Yahoo, MSN etc. to conceit-gleaned.php. The...
- Why is Your Website a Target? The SEO Value of a Website
Research Sucuri, 24 Jun 2019
Website security is what we eat, sleep, and breathe. It’s what we do best because we deal with hacked websites every single day, thousands of them. Among the various types and evolution in attack scenarios, one has remained the same for ...
- Spam Injector Masquerading as Google Analytics
Research Sucuri, 21 Jun 2019
The domain en-google-analytic[.]com , currently sinkholed by a security intelligence company, has been observed by our team to be part of a mass spam injection campaign. This attack was active as far back as February 2016 according to th...
- Malware vs Virus: What’s the Difference?
Research Sucuri, 21 Jun 2019
There appears to be a general misunderstanding among internet users about the difference between malware and viruses. The two terms are often used interchangeably and to an extent, this is perfectly fine. This article seeks to clarify th...
- Malware Infection from One Directory Up
Research Sucuri, 18 Jun 2019
Malicious code can reside anywhere on the site - not just in the web directory of the folder. During a recent incident response, all pages of a customer’s site were getting redirected to random URLs, making the problem hard to isolate at...
- Lightbox Adware - From Innocent Scripts to Malicious Redirects
Research Sucuri, 17 Jun 2019
It’s no news that webmasters commonly make use of external scripts to add more features to their site, but things can turn out for the worse quite easily. What if other scripts start behaving the same? What if they start to use your webs...
- Hiding a Hacktool Using a .jpg Extension
Research Sucuri, 17 Jun 2019
Hackers will do anything to hide their intentions behind the files they upload to compromised websites. This time, we’ve found a hacktool hidden inside a .jpg file. As expected, the file was found inside the “images” directory of WordPre...
- Why Do Hackers Hack? - 3 Reasons Explained
Research Sucuri, 14 Jun 2019
When considering why hackers are attacking websites, you might think that there’s a specific reason they target you as a website owner-your business, your reputation, or your information. But the truth is, hacks don’t often singled out s...
- FTP Logs Used to Determine Attack Vector
Research Sucuri, 10 Jun 2019
Logs can be very useful because they are a record of what was done by whom. They are especially useful when you need to find out more on how a website has been compromised. Since our job at Sucuri is to clean website malware, we don’t ha...
- Korean Gambling and Call Girl Spam on Hacked and Non-hacked Sites
Research Sucuri, 7 Jun 2019
This blog post talks about how a web spam campaign that targets only one country may create problems for sites owners around the world - even if their site is not hacked. It all began with a pretty regular sample of an infected WordPress...
- OS Command Injection in WP-Database-Backup
Research Sucuri, 4 Jun 2019
On May 28th, a critical OS Command Injection vulnerability affecting the WP-Database-Backup plugin was disclosed to the public by the Wordfence team. This is a very nasty bug which made it possible for a bad actor to gain full control of...
- WordPress Hacks: 5 Ways to Protect WordPress from Hacking
Research Sucuri, 31 May 2019
WordPress is one of the most popular content management systems (CMS) out there. That’s why it is vital to prevent WordPress hacking. Statistically, over 33% of websites currently run on WordPress. This post is not a “one size fits all” ...
- Malware-Serving Spam to Search Engine Bots
Research Sucuri, 31 May 2019
We recently discovered this malware with a list of IP ranges belonging to search engines that are serving them SEO spam. It even takes a snapshot of the website it’s on and uses that as a template so the pages look like they are a part o...
- PHP Backdoor Evaluates XOR Encrypted Requests
Research Sucuri, 29 May 2019
In the past, we’ve mentioned how the PHP XOR bitwise operator (represented by the caret ^) can be used to encrypt a malware’s source code. This operator makes it more difficult to determine if encrypted code is malicious, or if it is try...
- Malware Campaign Evolves to Target New Plugins: May 2019
Research Sucuri, 28 May 2019
A long-lasting malware campaign targeting deprecated, vulnerable versions of plugins continues to be leveraged by attackers to inject malicious scripts into affected websites. Easily automated vulnerabilities are the first choice for bad...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.