HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,878 reports kept since 2009. Updated automatically every 10 minutes. Last checked 1 min ago.
- JetHost Partners with Patchstack for Proactive WordPress Security
Research Patchstack, 4 Mar 2026
We’re excited to announce that JetHost has partnered with Patchstack to bring proactive vulnerability protection to WordPress websites hosted on its platform. JetHost is a modern hosting provider built by industry veterans with more than...
- Vulnerability & Patch Roundup - February 2026
Research Sucuri, 28 Feb 2026
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- BigWetFish Hosting Partners with Patchstack for WordPress Security
Research Patchstack, 27 Feb 2026
We’re thrilled to announce that BigWetFish Hosting, a trusted UK & Ireland-based web hosting provider known for fast performance, dependable support, and WordPress-optimized hosting, has integrated Patchstack for proactive WordPress vuln...
- ManageWP Partners with Patchstack for Protection at Scale
Research Patchstack, 19 Feb 2026
ManageWP has been making the lives of WordPress professionals and agencies easier for years within the GoDaddy ecosystem - helping them manage updates, backups, monitoring, and reporting at scale. Today, we’re excited to announce that it...
- Zone.ee Partners with Patchstack for Automatic WordPress Protection
Research Patchstack, 17 Feb 2026
We’re excited to announce a new partnership with Zone.ee, one of the leading hosting providers in the Baltics, known for delivering reliable infrastructure and user-friendly tools to businesses, developers, and agencies. Through this par...
- Grid Design Agency Partners with Patchstack to Strengthen WordPress Security
Research Patchstack, 2 Feb 2026
We’re happy to share that Grid Design Agency, a cutting-edge brand and website development agency based in London, the UK, has just introduced Patchstack to secure its clients’ websites. Known for building high-performing, design-led Wor...
- Case study: Wolf Agency’s proactive approach blocks 67k+ threats in 30 days with Patchstack
Research Patchstack, 2 Feb 2026
At Wolf Agency, proactive thinking isn’t a buzzword. The agency manages WordPress websites for clients who want to focus on growing their businesses, not worrying about technical details or security incidents. While Wolf Agency already h...
- Vulnerability & Patch Roundup - January 2026
Research Sucuri, 1 Feb 2026
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- Shadow Directories: A Unique Method to Hijack WordPress Permalinks
Research Sucuri, 30 Jan 2026
Last month, while working on a WordPress cleanup case, a customer reached out with a strange complaint: their website looked completely normal to them and their visitors, but Google search results were showing something very different. I...
- SQL Injection Vulnerability in Quiz and Survey Master (QSM) Plugin Affecting 40k+ Sites
Research Patchstack, 29 Jan 2026
This blog post is about a Subscriber+ SQL injection vulnerability in the Quiz and Survey Master (QSM) plugin. If you’re a QSM user, please update to at least version 10.3.2. This vulnerability was discovered and reported by Patchstack Al...
- Case study: How xCloud secured managed WordPress hosting and blocked 53k+ threats with Patchstack
Research Patchstack, 28 Jan 2026
At xCloud, security has always been a core part of the managed hosting promise. As the platform grew and began managing thousands of WordPress sites, security needed to scale just as fast. To deliver proactive, real-time protection witho...
- The Myth of Secure Hosting - Only 26% of Vulnerability Attacks Blocked By Hosts
Research Patchstack, 23 Jan 2026
“Secure hosting” is a phrase that’s increasingly used, and most hosts offer some level of security as part of their services. This mostly refers to known security suites like Cloudflare or in-house firewall solutions. But most of these s...
- Critical Arbitrary File Upload Vulnerability in RealHomes CRM Plugin Affecting 30k+ Sites
Research Patchstack, 22 Jan 2026
This blog post is about a Subscriber+ arbitrary file upload vulnerability in the RealHomes CRM. If you’re a RealHomes CRM user, please update to at least version 1.0.1. This vulnerability was discovered and reported by Patchstack Allianc...
- Critical Privilege Escalation Vulnerability in Modular DS plugin affecting 40k+ Sites exploited in the wild
Research Patchstack, 14 Jan 2026
This blog post is about an Unauthenticated Privilege Escalation vulnerability in the Modular DS plugin. Patchstack has issued a mitigation rule to protect against exploitation of this vulnerability. If you’re a Modular DS user, please up...
- Malware Intercepts Googlebot via IP-Verified Conditional Logic
Research Sucuri, 13 Jan 2026
Some attackers are increasingly moving away from simple redirects in favor of more “selective” methods of payload delivery. This approach filters out regular human visitors, allowing attackers to serve malicious content to search engine ...
- Google Sees Spam, You See Your Site: A Cloaked SEO Spam Attack
Research Sucuri, 8 Jan 2026
We recently handled a case where a customer reported strange SEO behavior on their website. Regular visitors saw a normal site. No popups. No redirects. No visible spam. However, when they checked their site on Google, the search results...
- Case study: How Libya’s Leading Host - Libyan Spider - Blocked 65k+ Threats with Patchstack
Research Patchstack, 8 Jan 2026
As Libya’s leading hosting and domain provider, Libyan Spider supports a rapidly growing WordPress ecosystem. Following national compliance trends and market demand encouraging businesses to establish an online presence, the company saw ...
- Fake Browser Updates Targeting WordPress Administrators via Malicious Plugin
Research Sucuri, 8 Jan 2026
We recently investigated a case involving a WordPress website where a customer reported persistent fake pop-up notifications appearing on their site. The warnings were urging them to update their browser (Chrome or Firefox), even though ...
- Seahawk Media Partners with Patchstack to Strengthen WordPress Security
Research Patchstack, 7 Jan 2026
We’re happy to share that Seahawk Media, a large WordPress agency serving businesses and hosting providers worldwide, has started using Patchstack to secure client websites. Seahawk Media specialises in white-label WordPress services for...
- Vulnerability & Patch Roundup - December 2025
Research Sucuri, 1 Jan 2026
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- Critical Arbitrary File Upload Vulnerability in Motors Theme Affecting 20k+ Sites
Research Patchstack, 17 Dec 2025
This blog post is about a Subscriber+ arbitrary file upload vulnerability in the Motors theme. If you’re a Motors theme user, please update to at least version 5.6.82. This vulnerability was discovered and reported by Patchstack Alliance...
- How to Run a Security Test and Set Up Continuous Monitoring
Research Sucuri, 15 Dec 2025
Many website owners follow a similar “security plan,” even if they don’t call it that. They launch the site, add a couple of plugins, and just hope nothing goes wrong. The issue is that modern website hacks don’t make themselves obvious....
- How to Protect Your WordPress Site From a Phishing Attack
Research Sucuri, 13 Dec 2025
If you run a website, manage a business inbox, or even just use online banking, you’ve already lived in the phishing era for a long time. The only thing that’s changed is the polish. Phishing scams have moved past those obviously fake “p...
- WordPress Auto-Login Backdoor Disguised as JavaScript Data File
Research Sucuri, 10 Dec 2025
During a recent investigation, we discovered a sophisticated WordPress backdoor hidden in what appears to be a JavaScript data file. This malware automatically logs attackers into administrator accounts without requiring any credentials....
- Privilege Escalation Vulnerability in Soledad Theme Affecting 50k+ Sites
Research Patchstack, 10 Dec 2025
This blog post is about an Subscriber+ privilege escalation vulnerability in the Soledad theme. If you’re a Soledad theme user, please update to at least version 8.6.9.1. This vulnerability was discovered and reported by Patchstack Allia...
- Vulnerability & Patch Roundup - November 2025
Research Sucuri, 30 Nov 2025
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- How to Fix the ERR_TOO_MANY_REDIRECTS Error
Research Sucuri, 13 Nov 2025
Encountering the ERR_TOO_MANY_REDIRECTS error (also called a redirect loop error) can be frustrating, especially when your website was working fine just moments ago. This issue is common across browsers such as Chrome, Firefox, and Edge ...
- Critical: Remote Code Execution via Malicious Obfuscated Malware in Imunify360 AV (AI-bolit)
Research Patchstack, 12 Nov 2025
Update (Nov 14) In addition to the documented RCE via the file-scanner deobfuscation logic, the database scanner (imunify_dbscan.php) was also vulnerable, and vulnerable in the exact same way. This means: This makes the issue far more se...
- PHP Object Injection Vulnerability in MediCenter Theme Affecting 10k+ Sites
Research Patchstack, 12 Nov 2025
This blog post is about an unauthenticated PHP object injection vulnerability in the MediCenter theme. If you’re a MediCenter theme user, please update the plugin to version 15.2. The vulnerabilities mentioned here were discovered and re...
- How to Choose WordPress Caching Options
Research Sucuri, 12 Nov 2025
If you want a faster WordPress site, caching belongs at the center of your performance plan. It reduces the work your server has to do and turns slow, dynamic page builds into quick, static responses. On many unoptimized sites, that shif...
- Slot Gacor: The Rise of Online Casino Spam
Research Sucuri, 7 Nov 2025
Online casino spam has been without a doubt one of the most prevalent types of spam content that we’ve seen on infected websites in recent years. An extremely common method of promoting low-quality or otherwise undesirable websites is fo...
- Vulnerability & Patch Roundup - October 2025
Research Sucuri, 31 Oct 2025
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- Two Critical Vulnerabilities in WordPress King Addons for Elementor Plugin Affecting 10k+ Sites
Research Patchstack, 30 Oct 2025
The TI WooCommerce Wishlist plugin, with over 100,000 active installs, is vulnerable to an unauthenticated file upload vulnerability (CVE-2025-47577).
- New: Patchstack Web Host Integration Unlocks Proactive Website Security with Industry-Leading Upsell Conversions
Research Patchstack, 28 Oct 2025
Most web hosts already promise speed, uptime, and reliability. But in 2025, customers expect to see security, not just trust that it’s there. Unfortunately, the majority of WordPress attacks bypass standard hosting defenses. In our own s...
- PHP Object Injection Patched in Quiz and Survey Master Plugin Affecting 40k+ Sites
Research Patchstack, 9 Oct 2025
The WP Job Portal plugin, with over 8,000 active installs, is vulnerable to unauthenticated SQL injection and arbitrary file read vulnerability.
- Malvertising Campaign Hides in Plain Sight on WordPress Websites
Research Sucuri, 4 Oct 2025
Recently, one of our customers noticed suspicious JavaScript loading across their WordPress website. Visitors were being served third-party scripts that the site owner never installed. After investigation, we discovered the infection ori...
- Vulnerability & Patch Roundup - September 2025
Research Sucuri, 30 Sep 2025
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- Security as a Hosting Differentiator - Turning Security Into Profit
Research Patchstack, 30 Sep 2025
For hosting companies, security isn’t just about blocking hackers. It’s about protecting customers, keeping a reputation intact, and, in the right setup, adding new revenue. That was the focus of a recent Patchstack webinar that pulled t...
- Q3 2025’s Most Exploited WordPress Vulnerabilities and How Patchstack’s RapidMitigate Blocked Them
Research Patchstack, 30 Sep 2025
WordPress, powering over 40% of websites, is a prime target for cyberattacks. Virtual patches (vPatches) provide immediate protection against vulnerabilities in plugins and themes, ensuring site security while awaiting official fixes.
- Enhancing File Transfer Security with SSH Key Authentication
Research Sucuri, 30 Sep 2025
Attackers scan for TCP 22 and 2222 around the clock. When they find an open port, they launch credential-stuffing lists harvested from previous leaks, brute-force scripts, and even malware that hunts for hard-coded passwords in deploymen...
- Troubleshooting WordPress: How to Fix the White Screen of Death (WSoD)
Research Sucuri, 25 Sep 2025
Navigating to your WordPress site only to be met with the White Screen of Death (WSoD) can be a daunting experience. This error denies access to your site for both administrators and visitors, disrupting your website’s performance and us...
- Hidden WordPress Backdoors Creating Admin Accounts
Research Sucuri, 24 Sep 2025
During a recent cleanup of a compromised WordPress website, we discovered two different malicious files designed to silently manipulate administrator accounts. Attackers often inject such backdoors to maintain persistent access to a site...
- Case Study: How vDisain Secured 200+ Client Websites and Reclaimed 15+ Hours Weekly with Patchstack
Research Patchstack, 22 Sep 2025
vDisain.ee, a fast-growing digital agency with offices in Estonia and Latvia provides website development, maintenance, and email marketing services. With clients spanning construction, manufacturing, and retail, and more than 200 active...
- Unauthenticated Broken Authentication Vulnerability in WordPress Jobmonster Theme
Research Patchstack, 18 Sep 2025
The TI WooCommerce Wishlist plugin, with over 100,000 active installs, is vulnerable to an unauthenticated file upload vulnerability (CVE-2025-47577).
- Unpatched Privilege Escalation in Service Finder Bookings Plugin
Research Patchstack, 3 Sep 2025
Critical WordPress security alert: Service Finder Bookings plugin allows unauthorized admin login. CVE-2025-23970 - no fix available yet! 🚫
- Vulnerability & Patch Roundup - August 2025
Research Sucuri, 1 Sep 2025
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- SQL Injection Vulnerability Patched in Paid Membership Subscriptions Plugin
Research Patchstack, 28 Aug 2025
The WP Job Portal plugin, with over 8,000 active installs, is vulnerable to unauthenticated SQL injection and arbitrary file read vulnerability.
- Creating an open alliance to secure the web
Research Patchstack, 27 Aug 2025
Over the years, we’ve witnessed many instances where critical security information fails to reach stakeholders as quickly as it should. Vulnerability databases help, but not all vulnerabilities are equal. Security teams from web hosts, p...
- What is Phishing?
Research Sucuri, 26 Aug 2025
Phishing is a serious threat to any industry. We have seen this topic appear in the news more each day. You might have already received a fraudulent email from what seemed to be your bank or even seen the hacking that took place during t...
- Locking Down the WordPress Login Page
Research Sucuri, 22 Aug 2025
Due to its flexibility, ease of use, and massive plugin ecosystem, WordPress is a favorite among bloggers, developers, and businesses alike. Given its popularity, attackers do not waste time guessing where sensitive assets live. By defau...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.