Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 9 min ago.

  1. Shell Logins as a Magento Reinfection Vector

    Research Sucuri, 31 May 2018

    Recently, we have come across a number of websites that were facing reinfection of a credit card information stealer malware within the following files: app/Mage.php; lib/Varien/Autoload.php; index.php; app/code/core/Mage/Core/functions....

  2. Cookie consent script used to distribute malware

    Research Sucuri, 29 May 2018

    Since the new website cookie usage regulations in the EU have come into place, many websites have added a warning on their website about how they use cookies on it and as well, ask for your consent. This has caused many website owners to...

  3. An Old Trick with a New Twist: Cryptomining Through Disguised URL Shorteners

    Research Sucuri, 22 May 2018

    As we have previously discussed on this blog, surreptitious cryptomining continues to be a problem as new methods emerge to both evade and hasten the ease of mining at the expense of system administrators, website owners, and their visit...

  4. Massive localstorage[.]tk Drupal Infection

    Research Sucuri, 8 May 2018

    After a series of critical Drupal vulnerabilities disclosed this spring, it’s not surprising to see a surge of massive Drupal infections like this one: Massive #Drupal infection that redirects to "Tech Support" scam via "js.localstorage[...

  5. A Puzzling Backdoor Upload

    Research Sucuri, 3 May 2018

    After a successful compromise, backdoors are frequently left behind and function as a point of re-entry into the website environment . These malicious pieces of code are a valuable tool for attackers and allow them to bypass any existing...

  6. Analysis of a Malicious Blackhat SEO Script

    Research Sucuri, 26 Apr 2018

    An enormous number of SEO spam infections are handled by us here at Sucuri. In our most recent hacked website trend report, we analyzed over 34,000+ websites and identified that 44% of all website infection cases were misused for black h...

  7. How to Avoid Malware & Reinfections: Update Your Site

    Research Sucuri, 24 Apr 2018

    Keeping your website updated is important if you want it to stay safe, secure, and running smoothly. This post will dive into why regular updates aren’t just a good idea, but a must-have for a clean and healthy website. We’ll check out h...

  8. From Baidu to Google’s Open Redirects

    Research Sucuri, 18 Apr 2018

    Last week, we described how an ongoing massive malware campaign began using Baidu search result links to redirect people to various ad and scam pages. It didn’t last long. Soon after the publication of that article, the bad actors change...

  9. Unwanted Ads via Baidu Links

    Research Sucuri, 10 Apr 2018

    The malware attack that began as an installation of malicious Injectbody/Injectscr WordPress plugins back in February has evolved since then. Some of the changes were documented as updates at the bottom of the original blog post, however...

  10. Hacked Website Trend Report - 2017

    Research Sucuri, 6 Apr 2018

    We are proud to be releasing our latest Hacked Website Trend Report for 2017. This report is based on data collected and analyzed by the Sucuri Remediation Group (RG), which includes the Incident Response Team (IRT) and the Malware Resea...

  11. Obfuscation Through Legitimate Appearances

    Research Sucuri, 4 Apr 2018

    Recently, I analyzed a malware sample provided by our analyst Edward C. Woelke and noticed that it had been placed in a core WordPress folder. This seemed suspicious, since no such core WP file like it exists: ./wp-includes/init.php Dece...

  12. What is Virtual Hardening?

    Research Sucuri, 26 Mar 2018

    If you want to make your website security more robust, you need to think about hardening. To harden your website means to add different layers of protection to reduce the potential attack surface. Hardening often involves manual measures...

  13. GitHub Hosts Infostealers Part 2: Cryptominers and Credit Card Stealers

    Research Sucuri, 21 Mar 2018

    Update - March 28th, 2018: The fake Flash update files referenced in this post have been moved from GitHub to port.so[.]tl , and the bit.wo[.]tc script to byte.wo[.]tc . A few days ago, we reported that hacked Magento sites had been push...

  14. GitHub Hosts Infostealer

    Research Sucuri, 15 Mar 2018

    A few months ago, we reported on how cybercriminals were using GitHub to load a variety of cryptominers on hacked websites. We have now discovered that this same approach is being used to push binary “info stealing” malware to Windows co...

  15. Steps to Keep Your Site Clean: Access Points

    Research Sucuri, 13 Mar 2018

    Unfortunately, most website owners know what it’s like to have a site hacked - the panic, the rush to find anyone out there that can help, and the worry it causes. Maybe you were able to get your site back on track or had a company clean...

  16. Mail from the ‘Boss’ - A Classic Example of a $_POST Mailer Stealing CC Data

    Research Sucuri, 8 Mar 2018

    We often find mailer scripts while cleaning malicious code from websites. Some of them are easily discovered, while others are obfuscated or heavily encoded. These “mailers” allow bad actors to send unwanted emails from your domain, and ...

  17. Intro to Securing an Online Store - Part 2

    Research Sucuri, 6 Mar 2018

    Last year, we introduced the theme of Securing an Online Store . We talked about how to identify the potential risks and what to look out for. These principles can help in satisfying PCI DSS requirements 8 & 10: Requirement 8 - Identify ...

  18. The Impacts of Zero-Day Attacks

    Research Sucuri, 28 Feb 2018

    Last week, we explained what zero-day vulnerabilities and attacks are. Essentially, zero-day vulnerabilities exist in the wild, with no patch available to prevent hackers from exploiting it. Today, we would like to expand on the impacts ...

  19. New Guide on How to Clean a Hacked Website

    Research Sucuri, 26 Feb 2018

    Our mission at Sucuri is to make the internet a safer place and that entails cleaning up hacked websites. We have teams who actively research website vulnerabilities and who are eager to share with you some tips on how to clean your hack...

  20. Wikipedia Page Review Reveals Minr Malware

    Research Sucuri, 19 Feb 2018

    Since December, we’ve seen a number of websites with this funny looking obfuscated script injected at the very top of the HTML code (before the tag). This code is generated by the well-known JJEncode obfuscator, which was once quite popu...

  21. Unwanted Pop-ups Caused by Injectbody/Injectscr Plugins

    Research Sucuri, 12 Feb 2018

    On February 8th, 2018, we noticed a new wave of WordPress infections involving two malicious plugins: injectbody and injectscr . These plugins inject obfuscated scripts, creating unwanted pop-up/pop-unders. Whenever a visitor clicks anyw...

  22. How to Add Security to Your Client’s Websites

    Research Sucuri, 5 Feb 2018

    Website security has crossed the mind of nearly every website owner. However, as a website security company , we know that most webmasters come to us after the fact, when their website has already been compromised. Once hackers have take...

  23. Cloudflare[.]solutions Keylogger Returns on New Domains

    Research Sucuri, 24 Jan 2018

    A few months ago, we covered two injections related to the “cloudflare.solutions” malware: a CoinHive cryptominer hidden within fake Google Analytics and jQuery, and the WordPress keylogger from Cloudflare[.]solutions . This malware was ...

  24. Server-level Cryptominer Injections

    Research Sucuri, 22 Jan 2018

    During an investigation on a recent case, we came across a malware infection that came directly from the server. Upon further inspection, we found that there were at least two servers showing the same symptom: cryptominers had been autom...

  25. SQLi Vulnerability in YITH WooCommerce Wishlist

    Research Sucuri, 16 Jan 2018

    As part of our regular research audits for our Sucuri Firewall, we discovered an SQL Injection vulnerability affecting the YITH WooCommerce Wishlist plugin for WordPress. This plugin allows visitors and potential customers to make wish l...

  26. Malicious Website Cryptominers from GitHub. Part 2.

    Research Sucuri, 3 Jan 2018

    Recently we wrote about how GitHub/GitHub.io was used in attacks that injected cryptocurrency miners into compromised websites. Around the same time, we noticed another attack that also used GitHub for serving malicious code. Encrypted C...

  27. Reverse Javascript Injection Redirects to Support Scam on WordPress

    Research Sucuri, 21 Dec 2017

    Over the last few weeks, we’ve noticed a JavaScript injection in a number of WordPress databases, and we recently wrote about them in a Sucuri Labs Note. The campaign attempts to redirect visitors to a bogus Windows support page claiming...

  28. Javascript Injection Creates Rogue WordPress Admin User

    Research Sucuri, 14 Dec 2017

    Earlier this year, we faced a growing volume of infections related to a vulnerability in outdated versions of the Newspaper and Newsmag themes. The infection type was always the same: malicious JavaScript designed to display unauthorized...

  29. Reversed URLs Randomly Redirect to Scams

    Research Sucuri, 14 Dec 2017

    We are seeing hundreds of infected WordPress sites with the following scripts (in one line) injected in random places in wp_posts table. $vTB$I_919AeEAw2z$KX=function(n){if (typeof ($vTB$I_919AeEAw2z$KX.list[n]) == "string") return $vTB$...

  30. Using Google and Facebook to aid on distribution

    Research Sucuri, 11 Dec 2017

    Every now and then I check my spam mail box for interesting malware (yes, I receive a lot of phishing messages and alerts that my payments are overdue), but most of the time is more of the same, effortless malware, lousy written messages...

  31. Malicious Cryptominers from GitHub

    Research Sucuri, 8 Dec 2017

    Recently, a webmaster contacted us when his AVG antivirus reported that the JS:Miner-C [Trj] infection was found on their site. Our investigation revealed a hidden iframe had been injected into the theme’s footer.php file: wpupdates .git...

  32. Cloudflare[.]Solutions Keylogger on Thousands of Infected WordPress Sites

    Research Sucuri, 6 Dec 2017

    Update Dec. 8 2017: The cloudflare[.]solutions domain has now been taken down. A few weeks ago, we wrote about a massive WordPress infection that injected an obfuscated script pretending to be jQuery and Google Analytics. In reality, thi...

  33. WP-VCD Malware Comes with Nulled Themes

    Research Sucuri, 6 Dec 2017

    Recently we wrote about wp-vcd malware that created rogue WordPress admin users ( 100010010 ) and injected spam links. Our readers noticed that the “nulled” premium theme sites promoted by the injected links (and some other similar sites...

  34. Backdoor using paste site to host payload

    Research Sucuri, 30 Nov 2017

    Over the last months, we’ve been talking a lot about new ways to decode complex malwares that involve the usual PHP functions like eval, create_function, preg_replace, assert, base64_decode, etc. According to our latest reports “Backdoor...

  35. IPv6 address in malicious Javascript redirect

    Research Sucuri, 29 Nov 2017

    We recently came across a file that shows an interesting case with a Javascript malicious code injection in a website’s custom script file, though it’s not specific to any particular website software: Infected filename: ./paginas/rodape....

  36. Formidable Forms / Shortcodes Ultimate Exploits In The Wild

    Research Sucuri, 24 Nov 2017

    On Monday, November 20th, we were notified about a vulnerability that poses a serious security risk when the Shortcodes Ultimate and Formidable Forms plugins are used together on a single WordPress installation. Over the past couple of w...

  37. Fake jQuery and Google Analytics Hide Yet Another Cryptominer

    Research Sucuri, 24 Nov 2017

    This is a quick posts about yet another quite massive attack that installs CoinHive JavaScript Monero miners on compromised websites. You might have already read our blog posts on how such attacks were first detected and how they escalat...

  38. Risks For E-commerce Site Owners Through the Holidays

    Research Sucuri, 22 Nov 2017

    Shopping season is here, and with that, so is the opportunity for ecommerce site owners to grow their revenue and reputation. However, hackers are also busy infecting ecommerce websites with malware, such as: Credit Card Swipers Maliciou...

  39. How to Avoid Malicious Cyber Monday Campaigns

    Research Sucuri, 15 Nov 2017

    As consumers prepare to take advantage of the discounts and promotions for the Black Friday and Cyber Monday ecommerce holidays, bad actors are crafting fraudulent websites, phishing, and malware campaigns to capitalize on the profits. I...

  40. SQL Injection in bbPress

    Research Sucuri, 13 Nov 2017

    During regular audits of our Sucuri Firewall (WAF), one of our researchers at the time, Slavco Mihajloski, discovered an SQL Injection vulnerability affecting bbPress. If the proper conditions are met, this vulnerability is very easy to ...

  41. New wave of wp-vcd Malware

    Research Sucuri, 13 Nov 2017

    Recently we saw a new wave of a known malware that injects malicious WordPress admin users to vulnerable or compromised sites.The malware, well analysed by Manuel D’Orso (here), was being injected on default WordPress themes that are not...

  42. Why Attackers Hack Small Sites

    Research Sucuri, 8 Nov 2017

    You would never leave the front door to your house wide open when you’re not home would you? Doing so would allow criminals to seize the opportunity of stealing your valuables. That’s the same way you can look at website hacking. Leaving...

  43. New WordPress Security Guide

    Research Sucuri, 3 Nov 2017

    WordPress has become the most popular CMS and now powers over 28% of the web. With over 60 million downloads, its popularity makes it a prime target for malicious hackers that are looking for vulnerabilities to exploit. If an attacker is...

  44. Cryptominers on Hacked Sites - Part 2

    Research Sucuri, 25 Oct 2017

    Last month we wrote about how the emergence of website cryptocurrency miners resulted in hackers abusing the technology by injecting the CoinHive miners into compromised sites without the consent of the website owners. We reviewed two ty...

  45. Attackers leveraging WP Maintenance plugin to deface websites

    Research Sucuri, 25 Oct 2017

    Recently, during a website investigation, we detected that attackers have been modifying the database structure of WP Maintenance plugin (which is a very popular wordpress plugin which adds a “down for maintenance” or coming soon page fo...

  46. Malware Serving SEO Spam from External Sites

    Research Sucuri, 18 Oct 2017

    We handle an enormous number of SEO spam infections here at Sucuri. In Q3 of 2016, approximately 37% of all website infection cases were related to SEO spam campaigns through PHP, database injections or .htaccess redirects. An SEO spam i...

  47. Mayhem Malware Server Botnet Continues to Evolve

    Research Sucuri, 12 Oct 2017

    Three years ago, researchers at Yandex discovered a complex server infection, dubbed Mayhem, that embeds itself deep within a system by compiling a shared object and running as a service. This also allows the malware to operate under res...

  48. Credit Card Stealer Investigation Uncovers Malware Ring

    Research Sucuri, 10 Oct 2017

    During a recent investigation, I found a new piece of malicious code being used to steal credit card information from compromised Magento sites. What I didn’t know was how many domains would be uncovered as part of the malware campaign. ...

  49. Website Hosting: Security Awareness Can Reduce Costs

    Research Sucuri, 3 Oct 2017

    Website hosting security has matured in recent years. Naturally, the types of security issues have changed because of it. For example, cross-contamination over multiple shared hosting accounts used to be a major problem for large website...

  50. Fake Plugins, Fake Security

    Research Sucuri, 28 Sep 2017

    Update : The plugin name is fake and has nothing to do with the well-known WP-SpamShield plugin in the official WordPress plugin repository. WordPress users are becoming increasingly more aware of security threats and as a result, they a...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support