Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 1 min ago.

  1. How to Prevent Cross-Site Contamination for Beginners

    Research Sucuri, 1 Feb 2019

    What is Cross-Site Contamination? Cross-site contamination happens when a hacked site infects other sites on a shared server. Think of it as your kid in daycare catching the flu, next thing you know, everybody in the family has it as wel...

  2. Spam Injector Disguised as License Key in WordPress Website

    Research Sucuri, 29 Jan 2019

    Here at Sucuri, we clean WordPress websites every day. There are various types of common malware, but when we stumble upon a different scenario, our research team likes to dig deeper and conduct a complete investigation. A license key is...

  3. Improvements to SiteCheck Website Scanner

    Research Sucuri, 18 Jan 2019

    SiteCheck is Sucuri’s free website malware and security scanner offered to anyone who wants to scan their websites for malware and blacklist status. Last year, we improved SiteCheck’s speed and reliability. Today, we are excited to share...

  4. Free SuperCounters Widget Serves Unwanted Redirects to Dating Site

    Research Sucuri, 10 Jan 2019

    If we navigate way back into the recesses of our memory to the era of GeoCities websites and MySpace pages, we might distinctly recollect the popularity of the visitor-counting widget. Commonly displayed on homepages across the web, thes...

  5. Spam Injector Disguised as a License Key

    Research Sucuri, 7 Jan 2019

    A client reported some weird spam URLs injected on their WordPress website and after an investigation, it turned out that the hacker was hiding the encoded spam injector malware in the following theme file: ./wp-content/themes/toolbox/fu...

  6. My Website Was Hacked on Christmas Eve

    Research Sucuri, 24 Dec 2018

    Christmas is a wonderful time to spend with family and friends. A lot of kids look forward to opening their presents under the Christmas tree, but not all of them have a present to open. This is why our family started a charity project i...

  7. Clever SEO Spam Injection

    Research Sucuri, 17 Dec 2018

    It’s very common for us here at Sucuri to face SEO injections on almost any type of CMS-based site. Today, I’ll be presenting how one particularly ingenious malware manages to hide so well inside a WordPress website. The Traditional Appr...

  8. Localization and Customization of Credit Card Stealing Malware

    Research Sucuri, 6 Dec 2018

    Credit card stealing malware is becoming more and more customized. We’ve been regularly seeing injected scripts with URLs that either mimic or include a portion of the victim’s site domain. Sometimes the injected code also references the...

  9. Using Innocent Roles to Hide Admin Users

    Research Sucuri, 4 Dec 2018

    All across the internet, we find guides and tutorials on how to keep your WordPress site secure. Most of them approach the concept of user roles , but not many actually approach the capabilities of those roles. The way the capabilities a...

  10. Fear, Uncertainty, and Doubt

    Research Sucuri, 26 Nov 2018

    There’s a term for the practice of scaring potential customers into purchasing products or services they don’t need: FUD; fear, uncertainty, and doubt. This practice is widespread in the computer/IT industries at large, but is especially...

  11. Side Effects of the Site_url Hack

    Research Sucuri, 20 Nov 2018

    We\’ve been cleaning many sites infected by the so-called site_url hack-the result of the WP GDPR Compliance plugin vulnerability. The sites are broken because their static resource links point to some third party site. However, this is ...

  12. A Scam-Free Cyber Monday for Online Businesses

    Research Sucuri, 19 Nov 2018

    Every year we see an increase in website attacks during the holidays. While business owners see their sales go up due to promotional Black Friday and Cyber Monday campaigns, hackers are in the background working nonstop to create malicio...

  13. Hackers Change WordPress Siteurl to Pastebin

    Research Sucuri, 13 Nov 2018

    Last Friday, we reported on a hack that used a vulnerability in the popular WP GDPR Compliance plugin to change WordPress siteurl settings to erealitatea[.]net . At that time it was not clear who was behind the massive attack, since the ...

  14. Erealitatea[.]net Hack Corrupts Websites with WP GDPR Compliance Plugin Vulnerability

    Research Sucuri, 10 Nov 2018

    We have noticed a growing number of WordPress-based sites that have had their URL settings changed to hxxp://erealitatea[.]net . Further investigations show that the issue is related to a security vulnerability in the WP GDPR Compliance ...

  15. Website Security Best Practices: 10 Tips to Keep Your Site Safe

    Research Sucuri, 7 Nov 2018

    Having a website has become easier than ever due to the proliferation of great tools and services in the web development space. Content management systems (CMS) like WordPress, Joomla!, Drupal, Magento, and others allow business owners t...

  16. New WordPress Security Email Course

    Research Sucuri, 5 Nov 2018

    Recent statistics show that over 32% of website administrators across the web use WordPress. Unfortunately, the CMSs popularity comes at a price - attackers often seek out vulnerabilities to exploit and target unhardened WordPress sites....

  17. Fake Wp.org/jquery.js

    Research Sucuri, 30 Oct 2018

    There is a long-lasting malware campaign (dating back to at least 2016 ) that injects fake jQuery scripts: www.XX[X]wp[.]org/jquery.js "> Where XX[X] are 2 or 3 random characters. This Twitter thread mentions some of them: Empty JS injec...

  18. Saskmade[.]net Redirects

    Research Sucuri, 26 Oct 2018

    Earlier this week, we published a blog post about an ongoing massive malware campaign describing multiple infection vectors that it uses. This same week, we started detecting new modifications of the scripts injected by this attack. The ...

  19. Multiple Ways to Inject the Same Tech Support Scam Malware

    Research Sucuri, 23 Oct 2018

    Last month, we shared information about yet another series of ongoing massive infections using multiple different vectors to inject malicious scripts into WordPress websites. Shortly after, the campaign changed the domain names used in i...

  20. Creating a Response Plan You Can Trust

    Research Sucuri, 19 Oct 2018

    As a website owner, you may have experienced your website being down for any number of reasons. Maybe due to errors in code, server related difficulties or even being under attack from bad actors. I once shared my own experience of a hac...

  21. Malicious Redirects from NewShareCounts.com Tweet Counter

    Research Sucuri, 16 Oct 2018

    When Twitter announced their new design for “Tweet” and “Follow” buttons back in October 2015, marketers across the web developed a mild anxiety-the new design came with a decision to nuke their beloved Tweet count feature. Social signal...

  22. Obfuscated JavaScript Cryptominer

    Research Sucuri, 9 Oct 2018

    During an incident response investigation, we detected an interesting piece of heavily obfuscated JavaScript malware. Once decoded, we found out that cryptominers were running on visitor’s computers when they accessed our customer’s webs...

  23. Backdoor Uses Paste Site to Host Payload

    Research Sucuri, 18 Sep 2018

    Finding backdoors is one of the biggest challenges of a website security analyst, as backdoors are designed to be hidden in case the malware is found and removed. Website Backdoors A backdoor is a piece of malware that attackers leave be...

  24. Multi-Vector WordPress Infection from Examhome

    Research Sucuri, 18 Sep 2018

    This September, we’ve been seeing a massive infection wave that injects malicious JavaScript code into .js, .php files and the WordPress database.> The script looks like this: eval(String.fromCharCode(118, 97, 114, 32, 115, 111, 109, 101...

  25. Outdated Duplicator Plugin RCE Abused

    Research Sucuri, 14 Sep 2018

    We’re seeing an increase in the number of cases where attackers are disabling WordPress sites by removing or rewriting its wp-config.php file. These cases are all linked to the same vulnerable software: WordPress Duplicator Plugin . Vers...

  26. Unsuccessfully Defaced Websites

    Research Sucuri, 13 Sep 2018

    Defaced websites are a type of hack that is easy to notice and a pain for website owners. Recently, we came across some defacement pages with a peculiar JavaScript injection included in the source code. What is a Defacement? Website defa...

  27. New Guide on How to Use the Sucuri WordPress Security Plugin

    Research Sucuri, 11 Sep 2018

    Sucuri has always been active in the WordPress community. We’ve attended WordCamps around the world, created tools and features specifically for WordPress, and have maintained a free WordPress security plugin with over 400k installations...

  28. “Google Fonts” popup leads to malware

    Research Sucuri, 10 Sep 2018

    A recent malware injection in a client\’s WordPress file was found to be targeting website visitors that were using the Google Chrome browser to access the infected website. It uses Javascript to detect the visitor\’s use of Google Chrom...

  29. WordPress Database Upgrade Phishing Campaign

    Research Sucuri, 4 Sep 2018

    We have recently been notified of phishing emails that target WordPress users. The content informs site owners that their database requires an update and looks like this: The email’s appearance resembles that of a legitimate WordPress up...

  30. Core Integrity Verifications

    Research Sucuri, 28 Aug 2018

    In order to clean a malware infection, the first thing we need to know is which files have been compromised. At Sucuri, we use several techniques including whitelists, blacklists, and anomaly checks. In this blog post, we’re going to be ...

  31. Massive WordPress Redirect Campaign Targets Vulnerable tagDiv Themes and Ultimate Member Plugins

    Research Sucuri, 22 Aug 2018

    This August, we’ve seen a new massive wave of WordPress infections that redirect visitors to unwanted sites. When redirected, users see annoying pages with random utroro[.]com addresses and fake reCAPTCHA images. The messages and content...

  32. Fake Plugins with Popuplink.js Redirect to Scam Sites

    Research Sucuri, 17 Aug 2018

    Since July, we’ve been observing a massive WordPress infection that is responsible for unwanted redirects to scam and ad sites. This infection involves the tiny.cc URL shortener, a fake plugin that has been called either “ index ” or “ w...

  33. How to Improve Your Website Security Posture - Part I

    Research Sucuri, 14 Aug 2018

    Have you ever wondered if your website security posture is adequate enough? The risk of having a website compromise is never going to be zero. However, as a webmaster, you can play an important role in minimizing the chances of a website...

  34. Fake Cloudflare Injection

    Research Sucuri, 8 Aug 2018

    Seeing malicious campaigns using domain names that resemble big market players is not news anymore. This time I\’ll talk about the new redirects of cloudflare.pw .**** The domain, registered in 2017, has been used as a doorway to other s...

  35. Cookie Consent Script Used to Distribute Malware

    Research Sucuri, 7 Aug 2018

    Most websites today use cookies. Since May 25th, 2018, all websites that do business in the European Union (EU) had to make some changes to be compliant with the EU General Data Protection Regulation (GDPR). Even though cookie usage is m...

  36. Cryptominers: Binary-Process-Cron Variants and Methods of Removal

    Research Sucuri, 2 Aug 2018

    This post provides a brief overview of how to manually remove server-side cryptominers and other types of Binary-Process-Cron malware from a server. Unlike browser-based JavaScript cryptominers that have been injected into a web page, a ...

  37. Obfuscated JavaScript Crypto Miner

    Research Sucuri, 1 Aug 2018

    During an incident response investigation, we detected an interesting piece of heavily obfuscated JavaScript malware. Once decoded, Crypto Miners were ran on customers visiting the website. By looking at the following malware this can be...

  38. RawGit CDN is Abused by CryptoLoot Cryptominers

    Research Sucuri, 31 Jul 2018

    Recently, we came across another way to use files from GitHub repositories in malware infections. This time the infections weren’t via GitHub.io, raw.githubusercontent.com, or github.com/ / /raw/ URLs. The new trick involved a third-part...

  39. Hardening WordPress on Apache, Nginx, or IIS

    Research Sucuri, 23 Jul 2018

    Server configuration files allow administrators to restrict access and make changes at the server level. Depending on the server software you use, there are different configuration files that instruct the server how to respond to request...

  40. Hiding Malware Inside Images on GoogleUserContent

    Research Sucuri, 18 Jul 2018

    If you have been following our blog for a long time, you might remember us writing about malware that used EXIF data to hide its code. This technique is still in use. Let us show you a recent example. Contaminated Pac-Man This code was f...

  41. Using Innocent roles to hide admin users

    Research Sucuri, 18 Jul 2018

    All across the internet we find guides and tutorials on how to keep your WordPress site secure, and they all approach the concept of user roles, but not many actually approach the capabilities of those roles. The way the capabilities are...

  42. Persistent Malicious Redirect Variants

    Research Sucuri, 16 Jul 2018

    It’s always nice to meet an old friend or someone you used to know well. You have news to share and talk about, stories to tell, etc. But what if your “old friend” was on the criminal side of things and you are meeting him more often tha...

  43. Ask Sucuri: How Do You Find Website Backdoors?

    Research Sucuri, 11 Jul 2018

    A website backdoor is malicious code injected into a website to allow unauthorized access. These hidden entry points can give attackers full control over your site, making them extremely dangerous. Today, we want to focus on the essentia...

  44. WordPress Update - 4.9.7 Security & Maintenance Release

    Research Sucuri, 5 Jul 2018

    The WordPress team has just released a critical security and maintenance update to resolve a number of bugs and security issues. Included in this release is a patch that protects against a vulnerability allowing bad actors to delete file...

  45. What are Website Backdoors?

    Research Sucuri, 26 Jun 2018

    When a site gets compromised, the attackers will often leave some piece of malware behind to allow them access back to the site. Hackers want to leave a door open to retain control of the website and to reinfect it continuously. This typ...

  46. Why You Should Care about Website Security on Your Small Site

    Research Sucuri, 21 Jun 2018

    Most people assume that if their website has been compromised, there must have been an attacker evaluating their site and looking for a specific vulnerability to hack. Under most circumstances however, bad actors don’t manually hand-pick...

  47. Magento Credit Card Stealer Reinfector

    Research Sucuri, 19 Jun 2018

    In the past few months, we have frequently seen how attackers are infecting Magento installations to scrape confidential information such as credit cards, logins, and PayPal credentials. That is why we have reported on a credit card stea...

  48. Hackers Are Just as Vulnerable as You

    Research Sucuri, 15 Jun 2018

    I came across some interesting defacement pages recently and noticed a peculiar JavaScript injection included within each source code of the defaced websites. As shown below, this JavaScript injection was peculiar as it seemingly provide...

  49. Fake Font Dropper

    Research Sucuri, 14 Jun 2018

    A website owner reached out to us to investigate a weird behavior on their site. It was randomly showing a popup window for a missing font and telling the visitors that they are unable to view the content of the site because their own co...

  50. JQuory: Cryptomining in Nulled Themes and Plugins.

    Research Sucuri, 5 Jun 2018

    Three months ago b>@ninoseki jquory.js files (yes, jqu o ry instead of jqu e ry). Coinhive(“I2OG8vGGXjF7wMQgL37BhqG5aVPjcoQL”) is trigged by “jquory.js”. haha.https://t.co/jLhCucoOYU pic.twitter.com/xMDrpcwde6 - にのせき (@ninoseki) Marc...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support