Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 8 min ago.

  1. Stored Cross-Site Scripting Vulnerability in WordPress 4.8.1

    Research Sucuri, 26 Sep 2017

    Update 11/03/2017: Read all about vulnerabilities and best practices to secure your website in our newly WordPress Security Guide today! During regular research audits for our Sucuri Firewall (WAF), we discovered a stored source-based Cr...

  2. Simple self updating hacktool

    Research Sucuri, 26 Sep 2017

    While working on a compromised website, it’s very common to encounter hacktools. Those are like the attackers’ swiss knife, allowing them to perform several tasks such as: DoS attacks, execute server level exploits and even simple filema...

  3. Hacked Websites Mine Cryptocurrencies

    Research Sucuri, 22 Sep 2017

    Cryptocurrencies are all the rage now. Bitcoin, altcoins, blockchain, ICO, mining farms, skyrocketing exchange rates - you see or hear this every day in the news now. Everyone seems to be trying to jump on this bandwagon. This trend resu...

  4. Mayhem malware still on the wild

    Research Sucuri, 19 Sep 2017

    Years ago, colleagues from Yandex introduced the concept of Mayhem infections. In that post, they provided very detailed information about the malware, its functionalities and capabilities. The interesting point of the malicious code, is...

  5. Malicious Backdoors: Fake Images and Strrev Functions

    Research Sucuri, 15 Sep 2017

    When a website is compromised, attackers frequently leave behind a backdoor - according to our research around 70% of all website hacks include a backdoor. These backdoors are not designed to attack a website or destroy data, instead, th...

  6. Old Themes, Abandoned Scripts and Pitfalls of Cleaning Serialized Data

    Research Sucuri, 13 Sep 2017

    Over the summer, we’ve seen waves of WordPress database infections that use vulnerabilities in tagDiv’s Newspaper/Newsmag themes or InterconnectIT Search and Replace scripts (searchreplacedb2.php). The injections range from ad scripts co...

  7. SEO spam loading from external site

    Research Sucuri, 13 Sep 2017

    Many websites get compromised and used for SEO in order to drive traffic to other websites that would usually be ranked very low or completely removed by Google due to their content. Recently I found some malware pulling spam content fro...

  8. Evil Self-Regenerating WordPress Administrator User

    Research Sucuri, 1 Sep 2017

    Attackers often aim to conceal their presence using different methods, such as injecting redirect scripts, creating spam pages, or hiding a mailer in checkout pages to steal credit cards; but this is not always the case. We’ve seen some ...

  9. Mining Adminers - Hackers Scan the Internet For DB Scripts

    Research Sucuri, 30 Aug 2017

    Hackers are constantly scanning the internet for exploitable sites, which is why even small, new sites should be fully patched and protected. At the same time, it is not feasible to scan the whole internet with 330+ million domains and b...

  10. When Online Shopping leads to Malware download

    Research Sucuri, 28 Aug 2017

    Recently, during an incident response process, we worked on an interesting Magento website. This site was reported to having a strange redirection when users visited the site. Without further ado, we started investigating the issue on th...

  11. Expired Domain Leads to WordPress Plugin Redirects

    Research Sucuri, 24 Aug 2017

    A malicious redirect is a snippet of code used by attackers with the intention of redirecting visitors to another site; a very common tactic seen in compromised websites. These redirects often take visitors to phishing, malware, or adver...

  12. Evasion Techniques in Phishing Attacks

    Research Sucuri, 22 Aug 2017

    We all know that we shouldn’t click on links from sketchy looking emails. But what if the website you’re viewing takes you to a spoofed page at the Apple ID store and asks for your login information to proceed? This tactic is called phis...

  13. Small One-liner Backdoor

    Research Sucuri, 21 Aug 2017

    During an incident response investigation, we detected an interesting backdoor that was small but had the potential to give the attacker full access to your website and all its content. Let’s review the backdoor content which was placed ...

  14. JavaScript Used to Generate Malicious Documents

    Research Sucuri, 17 Aug 2017

    When talking about compromised environments, we often think that the website itself is the end goal but that’s not always true. In some cases, attackers shift their focus to the user instead, especially when the website has lots of traff...

  15. Decoding Complex Malware - Step-by-Step

    Research Sucuri, 15 Aug 2017

    When cleaning websites, one of the most complicated parts of our job is ensuring we find all backdoors. Most of the time, attackers inject code into different locations to increase the chances of reinfecting the site and maintaining acce...

  16. Mobile Malware Targets eCommerce Websites & Users

    Research Sucuri, 11 Aug 2017

    A mobile malware is a malicious software that targets mobile/smartphones, tablets and similar devices. The attacks may vary from fatal damage to the OS (bricking) to leakage of sensitive and personal information, such as credit card, sav...

  17. PHP Script Nukes All Website Files

    Research Sucuri, 8 Aug 2017

    Most malware and spam that we come across has some sort of discernable purpose to it, usually something which benefits the attackers financially. This is often related to spam campaigns, credit card theft, spreading trojans/spyware or ph...

  18. Register My Backdoor - Unorthodox Invocation Mechanisms

    Research Sucuri, 26 Jul 2017

    Backdoors are found in 72% of infected websites, according to our latest reports. Backdoors are files left on the server by attackers in order to retain access to your site and reinfect it later, whenever they see fit. From time to time ...

  19. Labs Notes Monthly Recap - June/2017

    Research Sucuri, 20 Jul 2017

    This month, our Malware Research and Incident Response teams wrote about redirects that deliver malware and ads to visitors, as well as a backdoor method that attempts to hide from webmasters by using undefined variables. Sucuri Labs pro...

  20. Malicious Backdoor Hidden Inside Fake Image

    Research Sucuri, 17 Jul 2017

    During an incident response investigation, we detected an interesting backdoor that was hidden in a fake image. The attacker was quite creative in creating an attack that would work in two steps. The attacker created two files. The first...

  21. New Guide on How to Clean a Hacked Drupal Sites

    Research Sucuri, 11 Jul 2017

    Drupal is an open-source content management system and website builder with a unique structure that allows it to be highly flexible and extendible. For these reasons and more, it’s favored by technical developers and many large websites,...

  22. Evolution of Conditional Spam Targeting Drupal Sites

    Research Sucuri, 5 Jul 2017

    Last year we took a look at how attackers were infecting Drupal installations to spread their spam and keep their campaigns going by just including a malicious file in each visitor’s session. If your Drupal site has been compromised, we ...

  23. SQL Injection Vulnerability in WP Statistics

    Research Sucuri, 30 Jun 2017

    Update 11/3/2017: We are always looking for the latest to be shared with you and now we have released our WordPress Security Guide, were you can read all about vulnerabilities and best practices to keep your website protected. As part of...

  24. Securing Your Computer: A Primer for Windows and Mac Users

    Research Sucuri, 27 Jun 2017

    In this post we’ll be focusing on a part of your digital life that quietly influences everything else: the computer you use to log into accounts, manage websites, edit files, and store personal data. Even if you’re diligent about passwor...

  25. Unwanted “Shorte St” Ads in Unpatched Newspaper Theme

    Research Sucuri, 20 Jun 2017

    Unwanted ads are one of the most common problems that site owners ask us to solve. Recently, we’ve noticed quite a few requests to remove intrusive “ shorte st ” ads that they never installed on their sites themselves. My colleague Denis...

  26. Yet Another Expired Domain causes WP Plugin to Redirect Users

    Research Sucuri, 20 Jun 2017

    Malicious redirects are very common in compromised websites. Attackers try to take advantage of the site resources to promote spam, distribute other malware/backdoors, and perform all kinds of malicious activities. The type of attack des...

  27. When Your Plugins Turn Against You

    Research Sucuri, 13 Jun 2017

    Every day we face countless cases of sites getting compromised and infected by an attacker. From there, the sites can be used for various operations like spam campaigns, malware spreading or simply to damage your SEO ranking among other ...

  28. Undesired Redirects

    Research Sucuri, 13 Jun 2017

    Whether it is your own or a website you are visiting, undesired redirects and pop-ups are always annoying. The situation gets worse when your visitors start to get infected and your SEO ranking starts to drop. During an Incident Response...

  29. Labs Notes Monthly Recap - May/2017

    Research Sucuri, 6 Jun 2017

    Sucuri Labs provides website malware research updates directly from our teams on the front line. You can read past-monthly recaps to catch up on trends we look at every month. This month, our Malware Research and Incident Response teams ...

  30. How Undefined Variables Can Give You RCE

    Research Sucuri, 5 Jun 2017

    When investigating a compromised website, our team has to make sure that all malware and backdoors are cleared from the environment. In some instances, these backdoors are easier to detect than others, but that’s not always the case. Att...

  31. Spotlight: How a Digital Marketing Agency Secures Client Sites

    Research Sucuri, 2 Jun 2017

    Based in Melbourne, Australia for over 17 years, 24Digital knows what it takes to succeed in the ever-evolving digital marketing space which is no longer a world resting on desktop alone. The goal is to be an extension to every client’s ...

  32. The elegant dropper - reusable code for PHP shell installation

    Research Sucuri, 31 May 2017

    During our malware research role, we analyze hundreds (if not thousands) of malware samples every day. Quite often, highly-obfuscated techniques are used by attackers to avoid detection and maintain access to the compromised environment ...

  33. Simple $_COOKIE backdoor (variation)

    Research Sucuri, 30 May 2017

    There are many ways to develop a backdoor and virtually all of them share a similar goal - not to be discovered. To achieve that, some attackers are giving up on using $_POST and $_GET variables, obfuscation techniques, etc, and playing ...

  34. Personal Security Guide - Online Accounts

    Research Sucuri, 23 May 2017

    In our last post on browser security, we talked about how developing a broader security mindset can help keep your website safe. By taking steps to secure your online accounts you can prevent hackers from gaining unauthorized access to y...

  35. Personal Security Guide - Web Browsers

    Research Sucuri, 19 May 2017

    If your computer is infected, malware can spread to your website through text editors and FTP clients. Weak passwords are also vulnerable to brute force attacks, and using unsecured networks to access the internet can leave you exposed t...

  36. Website Availability and Security When Migrating Hosts

    Research Sucuri, 12 May 2017

    Website security is a continuous process. It’s not something that should be turned on when the time is right; rather integrated into the full scope of how you deploy a website, maintain it, and ensure the safety of your visitors. At Sucu...

  37. Tricky malvertising injections

    Research Sucuri, 10 May 2017

    When a website is compromised, one of the most interesting and challenging tasks we perform is identifying all malware to prevent attackers from regaining access to the resource. They may use different type of malicious codes and techniq...

  38. Client-Side or Server-Side Script?

    Research Sucuri, 3 May 2017

    We’ve already described several times how credit card stealing malware hides a data collecting script behind an image URL. When people see URLs that end with .jpg , .png , or .gif they normally don’t expect them to do anything malicious....

  39. Labs Notes Monthly Recap - Apr/2017

    Research Sucuri, 2 May 2017

    This month, our Malware Research and Incident Response teams wrote about several malware techniques that attempt to evade detection by focusing on small changes that website owners might miss. Examples include typos in domain names, unus...

  40. Website Malware: Unwanted Exit to YourBrexit

    Research Sucuri, 20 Apr 2017

    Some website hacks aim to make some political statements. Defacements are well known for this. Some infections redirect visitors to scam sites that push (usually counterfeit) goods or (often illegal) services. But what would you feel if ...

  41. Titles, Imprints and Marks Left by Attackers

    Research Sucuri, 18 Apr 2017

    Some attackers seem to like signing their scripts. This fact is especially true for defacements and backdoors, where attackers show their pride stating that they “owned” a site by signing their own malware. Sometimes they write their exp...

  42. Labs Notes Monthly Recap - Mar/2017

    Research Sucuri, 14 Apr 2017

    Every month we recap the latest posts on Sucuri Labs, written by our Malware Research Team (MRT) and Incident Response Team (IRT). Sucuri Labs provides website malware research updates directly from our teams on the front line. You can r...

  43. Malicious Image Defacement Hidden from Search Engines

    Research Sucuri, 11 Apr 2017

    After carefully designing a theme and images that represent your brand, nothing is worse than seeing a malicious image suddenly associated with your business or website. In a recent blog post, we discussed a case in which a lewd image ap...

  44. Ecommerce Security - Customer Data Breaches Using Images

    Research Sucuri, 6 Apr 2017

    Since late last year, there has been a steady rise in malware campaigns that aim to steal sensitive personal information and financial credentials. Attackers often insert pieces of malicious code in the middle of a shopping cart process,...

  45. WordPress Security - Unwanted Redirects via Infected JavaScript Files

    Research Sucuri, 4 Apr 2017

    We’ve been watching a specific WordPress infection for several months and would like to share details about it. The attacks inject malicious JavaScript code into almost every .js file it can find. Previous versions of this malware inject...

  46. WebSockets, Viagra and Fake CloudFlare CDN

    Research Sucuri, 3 Apr 2017

    Recently we’ve seen some WordPress websites displaying unwanted banners at the bottom of the page which appear 15 seconds after browsing the website. Those banners are being generated due to the following code being injected into the the...

  47. Spotting a Hidden SEO Hack: “Play One”

    Research Sucuri, 30 Mar 2017

    SEO hacks continue to plague websites as attackers abuse SERP rankings for their own gain. The time and effort spent by the website owner creating content, optimizing pages and building links is stolen by an attacker in an instant. For m...

  48. Malicious Subdirectories Strike Again

    Research Sucuri, 17 Mar 2017

    In a previous post, we illustrated how attackers were fetching information from compromised sites under their control to display spam content on other hacked websites. By adding malicious files into a directory and using the victim’s dat...

  49. Attackers Silently add new user with Administrator role to WordPress sites

    Research Sucuri, 16 Mar 2017

    Attackers tend to get smarter in order to avoid detection, as well as gain access to your WordPress site. They use legit functions of the WordPress core to create users, post spammy content, and other kinds of malicious activities. Most ...

  50. SEO Spam Campaign Exploiting WordPress REST API Vulnerability

    Research Sucuri, 15 Mar 2017

    Just over a week ago, WordPress released version 4.7.3 to patch multiple security issues. Despite the automatic update feature provided by many hosting companies, there are still many WordPress websites that have not been updated. In fac...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support