Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 2 min ago.

  1. Return to the City of Cron - Malware Infections on Joomla and WordPress

    Research Sucuri, 27 May 2019

    We recently had a client that had a persistent malware infection on their shared hosting environment that would re-infect the files quickly after we had cleaned them. The persistence was being created by a cron that was scheduled to down...

  2. Threat intelligence gathering from slight changes in malicious code samples

    Research Sucuri, 24 May 2019

    We found the following PHP backdoor in August 2018 along with other malware samples uploaded after hackers exploit a specific vulnerable WordPress plugin covered in this previous post. @include('cleartemp'); @unlink('cleartemp'); ?> It’s...

  3. .htaccess Injector on Joomla and WordPress Websites

    Research Sucuri, 23 May 2019

    During the process of investigating one of our incident response cases, we found an .htaccess code injection. It had been widely spread on the website, injected into all .htaccess files and redirecting visitors to the http[:]//portal-f[....

  4. Slimstat: Stored XSS from Visitors

    Research Sucuri, 21 May 2019

    The WordPress Slimstat plugin, which currently has over 100k installs, allows your website to gather analytics data for your WordPress website. It will track certain information such as the browser and operating system details, plus page...

  5. W97M/Downloader Malware Dropper Served from Compromised Websites

    Research Sucuri, 20 May 2019

    W97M/Downloader is part of a large banking malware operation that peaked in March 2016. Bad actors have been distributing this campaign for well over a year, which serves as a doorway to Vawtrak and Dridex banking trojans. This malware c...

  6. Who is Responsible for the Security of Your Website?

    Research Sucuri, 17 May 2019

    On a daily basis at Sucuri, we hear things like: “My host takes care of my website security.” “I have never been hacked, so why should I care?” Or here’s a personal favorite: “I’ll take care of it if (when) it happens.” Let’s be honest, ...

  7. Persistent Cross-site Scripting in WP Live Chat Support Plugin

    Research Sucuri, 15 May 2019

    During a routine research audits for our Sucuri Firewall, we discovered an Unauthenticated Persistent Cross-Site Scripting (XSS) affecting 60,000+ users of the WP Live Chat Support WordPress plugin. Current State of the Vulnerability Tho...

  8. WordPress Plugin Give - Stored XSS for Donors

    Research Sucuri, 15 May 2019

    ​​Give is a WordPress plugin which allows users to setup a donation page on a website. It currently has 60k installs. ​​During a recent audit of the plugin, we found a severe vulnerability which allows donors to inject arbitrary code on ...

  9. array_diff_ukey Usage in Malware Obfuscation

    Research Sucuri, 14 May 2019

    We discovered a PHP backdoor on a WordPress installation that contained some interesting obfuscation methods to keep it hidden from prying eyes: $zz1 = chr(95).chr(100).chr(101).chr(115).chr(116).chr(105).chr(110).chr(97).chr(116).chr(10...

  10. Multiple Vulnerabilities in the WordPress Ultimate Member Plugin

    Research Sucuri, 13 May 2019

    The Ultimate member plugin version 2.0.45 and lower is affected by multiple vulnerabilities, among them is a critical vulnerability allowing malicious users to read and delete your wp-config.php file, which can lead to a complete website...

  11. xmlrpc.php Brute Force Tool

    Research Sucuri, 9 May 2019

    We discovered a xmlrpc.php brute-force tool in a malicious PHP script that appears to have been uploaded months ago after a vulnerable GDPR plugin exploit: $data = $_POST['data']; $parameter = $_POST['parameter']; $domains = preg_split('...

  12. Persistent XSS via CSRF in WP Meta and Date Remover

    Research Sucuri, 7 May 2019

    During regular research audits for our Sucuri Firewall (WAF), we discovered a Cross Site Request Forgery (CSRF) leading to a persistent Cross Site Scripting vulnerability affecting 70,000+ users of the WP Meta and Date Remover plugin for...

  13. Cronjob Backdoors

    Research Sucuri, 3 May 2019

    Attackers commonly rely on backdoors to easily gain reentry and maintain control over a website. They also use PHP functions to further deepen the level of their backdoors. A good example of this is the shell_exec function which allows p...

  14. How Stolen Ecommerce Data is Sold on the Darknet

    Research Sucuri, 1 May 2019

    We have recently published posts regarding banking malware and some of the ways it uses compromised websites to infect victim’s devices (smartphones, computers, POS terminals). Now let us look into some of the methods that cybercriminals...

  15. Insufficient Privilege Validation in WooCommerce Checkout Manager

    Research Sucuri, 29 Apr 2019

    Due to the poor handling of a vulnerability disclosure, a new attack vector has appeared for the WooCommerce Checkout Manager WordPress plugin and is affecting over 60,000 sites. If you are using this plugin, we recommend that you update...

  16. Typo 3 Spam Infection

    Research Sucuri, 26 Apr 2019

    Here at Sucuri most of the malware that we deal with is on CMS platforms like: WordPress, Joomla, Drupal, Magento, and others. But every now and then we come across something a little different. Blackhat SEO Infection in Typo3 Just recen...

  17. Fake relatable domain used to distribute ads

    Research Sucuri, 26 Apr 2019

    Malicious users try to hide their malicious scripts in many ways these days, some more clever then others, in this case we look at a domain which looks like GoogleADS[.]com but it’s actually GoogleADSL[.]com, this was done to make the do...

  18. Plugins Added to Malicious Campaign

    Research Sucuri, 25 Apr 2019

    We continue to see an increase in the number of plugins attacked as part of a campaign that’s been active for quite a long time. Bad actors have added more vulnerable plugins to inject similar malicious scripts. Plugins Added to the Atta...

  19. Free Premium themes? There’s always a catch

    Research Sucuri, 25 Apr 2019

    OK, so we’ve all been there. We want something Premium, such as a paid version of an app or piece of software, but it would be great not having to pay for it, right? Well, we know that while there are some great pieces of software around...

  20. WP Plugin Hider

    Research Sucuri, 23 Apr 2019

    One of our analysts recently found an interesting injection that has been found on WordPress installations. Installed by hacker, it is used to hide a malicious plugin. that was installed by the hacker. In this instance the plugin was gen...

  21. Reset Email Account Passwords After a Website Malware Infection

    Research Sucuri, 22 Apr 2019

    It’s not uncommon for bad actors to use compromised websites to send large amounts of email spam. This can cause major headaches for website owners - spam can lead to the blacklisting of a web host’s mail server IPs, or the domain name i...

  22. Defunct Malware Can Cause Problems Too

    Research Sucuri, 18 Apr 2019

    Recently our incident response analyst Harshad Mane worked on a site that redirected users to a third-party malicious site whenever they logged into the WordPress admin interface. We found the culprit in the functions.php file of the act...

  23. Thousands of Redirecting Files

    Research Sucuri, 17 Apr 2019

    We recently cleaned a site where we found thousands of malicious files with the following content: header ( "HTTP/1.1 301 Moved Permanently" ) ; header ( "Location: hxxp://realprofit[.]su/" ) ; ?> and header ( "HTTP/1.1 301 Moved Permane...

  24. From .tk Redirects to PushKa Browser Notification Scam

    Research Sucuri, 15 Apr 2019

    In the past couple of years, we’ve been tracking a long-lasting campaign responsible for injecting malicious scripts into WordPress sites. This campaign leverages old vulnerabilities (patched a long time ago) found in a variety of outdat...

  25. SQL Injection in Advance Contact Form 7 DB

    Research Sucuri, 11 Apr 2019

    As part of our regular research audits for our Sucuri Firewall, we discovered an SQL injection vulnerability affecting 40,000+ users of the Advanced Contact Form 7 DB WordPress plugin. Current State of the Vulnerability This plugin saves...

  26. Attacks on Closed WordPress Plugins

    Research Sucuri, 10 Apr 2019

    The WordPress plugin repository team may “close” plugins and restrict downloads when they become aware of a security issue that the developer cannot fix quickly. However, bad actors are actively monitoring the WordPress plugin repository...

  27. DDoS Targeting WordPress Search

    Research Sucuri, 8 Apr 2019

    Have you ever stopped to think about how many resources a search engine has or if your website could handle the same amount of search traffic that Google does? Search engines play an important role on the internet and with how websites p...

  28. SQL Injection in Duplicate-Page WordPress Plugin

    Research Sucuri, 5 Apr 2019

    While investigating the Duplicate Page plugin, we have discovered a dangerous SQL Injection vulnerability. Though the plugin wasn’t abused externally, the vulnerability impacted over 800,000 sites. Its urgency is defined by the associate...

  29. Malware Campaigns Sharing Network Resources: r00ts.ninja

    Research Sucuri, 3 Apr 2019

    We recently noticed an interesting example of network infrastructure resources being used over a period of time by more than one large scale malware campaign (e.g redirected traffic, cryptomining). This was discovered when reviewing sour...

  30. April Fool’s Day - TYPO3 Overtakes WordPress as Most Attacked CMS Due to Popularity

    Research Sucuri, 1 Apr 2019

    Disclaimer : This is an April Fool’s Day blog post and not all the information below is accurate. If you are looking for updated information on CMSs and malware families, access our latest Website Hack Trend Report. It all started with a...

  31. Social Warfare Vulnerability Probes

    Research Sucuri, 29 Mar 2019

    After a recent disclosure of the Social Warfare plugin vulnerability, we’ve seen massive attacks that inject malicious JavaScripts into the plugin options. The vulnerability has been patched in version 3.5.3 of the plugin, so not all sit...

  32. Conditional redirection to an online pharmacy store

    Research Sucuri, 28 Mar 2019

    During an investigation, a client reported some weird behavior from all incoming visits during their Google search engine result clicks are instantly redirected to an online pharmacy store. This occurred with visits that were initiated b...

  33. Stored XSS Patched in WordPress 5.1.1

    Research Sucuri, 26 Mar 2019

    WordPress recently released an update, 5.1.1, which patches a stored XSS vulnerability in the platform’s comment system. Even 10 days after the release of this security patch, around 60% of all WordPress sites scanned by our services did...

  34. Super Amazon Banners Plugin Gone Rogue

    Research Sucuri, 26 Mar 2019

    During a recent investigation we found the plugin Super Amazon Banners to be serving malware/spam via the domain seoranker[.]info. We suspect that the domain expired and was registered by somebody else who is using it to serve the malwar...

  35. How to Choose a Website Security Provider

    Research Sucuri, 25 Mar 2019

    As more people are creating websites and becoming aware of website security, companies are popping up everywhere to help with the problem. And just like website security plugins, not all website security services are created equal. Here ...

  36. Multi-Vector Attack in Server Logs

    Research Sucuri, 25 Mar 2019

    We recently noticed an increase on suspicious requests in our logs which reveal a planned attack against the Social Warfare plugin. Bad actors added this brand new exploit to an existing campaign, which includes other vulnerable plugins ...

  37. Zero-Day Stored XSS in Social Warfare

    Research Sucuri, 21 Mar 2019

    A zero-day vulnerability has just appeared in the WordPress plugin world, affecting over 70,000 sites using the Social Warfare plugin. The plugin is vulnerable to a Stored XSS (Cross-Site Scripting) vulnerability and has been removed fro...

  38. 0day Vulnerability in Easy WP SMTP Affects Thousands of Sites

    Research Sucuri, 21 Mar 2019

    The Easy WP SMTP plugin authors have released a new update, fixing a very critical 0day vulnerability. When leveraged, this vulnerability gives unauthenticated attackers the power to modify any options of an affected site - ultimately le...

  39. More on Dnsden[.]biz Swipers and Radix Obfuscation

    Research Sucuri, 19 Mar 2019

    After recent publication of the Uncommon Radixes Used in Malware Obfuscation article, we found an interesting Twitter thread involving @EKFiddle and @Ledtech3 #EKFiddle [Regex update]: Added Radix Web Skimmer identified by @unmaskparasit...

  40. Arbitrary Directory Deletion in WP-Fastest-Cache

    Research Sucuri, 18 Mar 2019

    The WP-Fastest-Cache plugin authors released a new update, version 0.8.9.1 , fixing a vulnerability (CVE-2019-6726) present during its install alongside the WP-PostRatings plugin. According to seclists.org: “A successful attack allows an...

  41. Uncommon Radixes Used in Malware Obfuscation

    Research Sucuri, 15 Mar 2019

    Some JavaScript features allow for pretty interesting obfuscation techniques. For example, did you know that virtually any English word can be used as a valid number? I recently decoded a credit card stealing script injected at the botto...

  42. Insufficient Privilege Validation in SiteGround Optimizer & Caldera Forms Pro

    Research Sucuri, 13 Mar 2019

    While investigating the SiteGround Optimizer and Caldera Forms Pro plugins we have discovered a critical privilege escalation vulnerability. It was not being abused externally and impacts over 500,000 sites. It’s urgency is defined by th...

  43. From Fake Updates to Unwanted Redirects

    Research Sucuri, 8 Mar 2019

    At the end of February, we wrote about a massive wave of site infections that pushed fake browser updates. In the beginning of March, the attack evolved into redirecting site visitors to sketchy ad URLs. In WordPress, the injected script...

  44. How to Add SSL & Move WordPress from HTTP to HTTPS

    Research Sucuri, 6 Mar 2019

    Moving a WordPress website from HTTP to HTTPS should be a priority for any webmaster. Recent statistics show that over 33% of website administrators across the web use WordPress and many of these websites have still not added an SSL cert...

  45. Hacked Website Trend Report - 2018

    Research Sucuri, 4 Mar 2019

    We are proud to be releasing our latest Hacked Website Trend Report for 2018. This report is based on data collected and analyzed by the GoDaddy Security / Sucuri team, which includes the Incident Response Team (IRT) and the Malware Rese...

  46. Fake Browser Updates Push Ransomware and Bank Malware

    Research Sucuri, 28 Feb 2019

    Recently we came across a malicious campaign injecting scripts that push fake browser updates onto site visitors. This is what a typical fake update request looks like: Users see a message box that says it’s an “Update Center” for your b...

  47. Google Analytics and Angular in Magento Credit Card Stealing Scripts

    Research Sucuri, 26 Feb 2019

    Over the last few months, we’ve noticed several credit card-stealing scripts that use variations of the Google Analytics name to make them look less suspicious and evade detection by website owners. The malicious code is obfuscated and i...

  48. Hackers Use Fake Google reCAPTCHA to Cloak Banking Malware

    Research Sucuri, 21 Feb 2019

    The most effective phishing and malware campaigns usually employ one of the following two age-old social engineering techniques: Impersonation These online phishing campaigns impersonate a popular brand or product through specially craft...

  49. The Anatomy of Website Malware: An Introduction

    Research Sucuri, 7 Feb 2019

    We see a lot of files infected by website malware on a daily basis here at Sucuri Labs. What we don’t see is very many categories of infections. The purpose of this blog post series is to provide an overview of the most common infection ...

  50. Fake Parameters Conceal a Backdoor

    Research Sucuri, 5 Feb 2019

    We found this backdoor in the middle of the logrss.php file that defined the JDocumentRendererRSS class. ...function jregisterClass () { // merge arrays $info = array_merge($_REQUEST,$_COOKIE); // validate parameters if ( !isset($info['m...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support