Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 6 min ago.

  1. Stored XSS in WordPress Core

    Research Sucuri, 13 Mar 2017

    As you might remember, we recently blogged about a critical Content Injection Vulnerability in WordPress which allowed attackers to deface vulnerable websites. While our original disclosure only described one vulnerability, we actually r...

  2. Set your Cookie, Execute a Command

    Research Sucuri, 9 Mar 2017

    Backdoors evolve. They tend to get more complex, harder to understand and harder to decode, but this is not always the case. Most of the backdoors rely on PHP-enabled engine options that allow execution of commands. Also, those options d...

  3. vBulletin Used to Show Malicious Advertisements

    Research Sucuri, 6 Mar 2017

    In the past, we have seen a massive amount of vBulletin websites compromised through the VBSeo Vulnerability. Attackers have been infecting vBulletin websites since 2012 with this malware, and more recently with a new variation of the sa...

  4. Labs Notes Monthly Recap - Feb/2017

    Research Sucuri, 3 Mar 2017

    Every month we recap the latest posts on Sucuri Labs, written by our Malware Research Team (MRT) and Incident Response Team (IRT). The Sucuri Labs website provides technical analysis and industry updates directly from our teams on the fr...

  5. Monetized JavaScript Redirect to Free Porn Webcams for Mobile Devices

    Research Sucuri, 2 Mar 2017

    Attackers will do desperate and obvious things to boost the views of their ‘customers’. On a daily basis we find different malicious redirects (some are very well hidden, others not so much). The case with this JavaScript redirect is not...

  6. Ghost from the Past

    Research Sucuri, 28 Feb 2017

    Some sites may stay infected or not properly cleaned for years. Eventually, they come to us and we clean them. It doesn’t matter whether the malware is old or new. But old malware may tell stories for those who can read it. For example, ...

  7. SQL Injection Vulnerability in NextGEN Gallery for WordPress

    Research Sucuri, 27 Feb 2017

    As part of a vulnerability research project for our Sucuri Firewall (WAF), we have been auditing multiple open source projects looking for security issues. While working on the WordPress plugin NextGEN Gallery, we discovered a severe SQL...

  8. When malware injection goes wrong

    Research Sucuri, 23 Feb 2017

    Today while scanning a client’s website, I found a failed attempt by attackers to hide the location of a backdoor. It is very common for us to find backdoor uploaders on websites, as they are one of the principle ways attackers upload ma...

  9. Spam content injection

    Research Sucuri, 21 Feb 2017

    During a recent incident response investigation, we detected an infected website loading spam content from another location. The malware was responsible for fetching the spam and displaying it on the front page without the client’s knowl...

  10. Joomla Security - Pornography Spam Campaign in the Wild

    Research Sucuri, 20 Feb 2017

    One of the worst experiences for a website owner is finding out that the search results for your site have turned into a pharmacy, a fashion outlet, or even a porn dump. Those unwanted keywords are a result of Search Engine Poisoning (SE...

  11. WordPress Security - Fake TrafficAnalytics Website Infection

    Research Sucuri, 17 Feb 2017

    Several months ago, our research team identified a fake analytics infection, known as RealStatistics. The malicious Javascript injection looks a lot like tracking code for a legitimate analytics service. RealStatistics even set up fake a...

  12. .user.ini SPAM SEO Redirect

    Research Sucuri, 17 Feb 2017

    Since PHP 5.3.0, PHP includes support for configuration INI files on a per-directory basis that has the same effect (depending on the case) that the .htaccess files have on Apache. With that in mind, attackers are exploiting this feature...

  13. Backdooring sites using exotic php functions

    Research Sucuri, 16 Feb 2017

    Throughout the last few months, we published multiple articles about simple but powerful backdoors and how attackers get creative. Virtually in all cases, the code is designed to avoid detection and it’s not always highly encoded. Actual...

  14. New Guide on How to Fix Hacked Magento Sites

    Research Sucuri, 15 Feb 2017

    Ecommerce refers to websites that involve online purchases. This functionality sparks new challenges, concerns, and requirements for website security. Online shopping, to many people, is almost synonymous with a certain kind of risk - an...

  15. Labs Notes Monthly Recap - Jan/2017

    Research Sucuri, 14 Feb 2017

    Every month we recap the latest posts on Sucuri Labs, written by our Malware Research Team (MRT) and Incident Response Teams (IRT). The Sucuri Labs website provides technical analysis and industry updates directly from our teams on the f...

  16. Hiding malicious code from the user using white spaces

    Research Sucuri, 14 Feb 2017

    Over the years, attackers have used different techniques for hiding malicious files on websites. They obfuscated code, changed legit functions to execute malware, modified whole core files to execute their malicious activity and much mor...

  17. RCE Attempts Against the Latest WordPress REST API Vulnerability

    Research Sucuri, 9 Feb 2017

    We are starting to see remote command execution (RCE) attempts trying to exploit the latest WordPress REST API Vulnerability. These RCE attempts started today after a few days of attackers (mostly defacers) rushing to vandalize as many p...

  18. JavaScript Injections Leads to Tech Support Scam

    Research Sucuri, 9 Feb 2017

    During a recent malware investigation, we found some interesting obfuscated Javascript code. This code pretends to appear as part of the popular AddThis social sharing plugin, using it in URL naming conventions and an image file. The mal...

  19. Checking blacklisted domains or IP for spamming

    Research Sucuri, 8 Feb 2017

    Often times we will encounter websites that have been injected with a redirect and these can vary from blackhat SEO tactics for boosting domain rankings all the way to phishing pages trying to steal login credentials. In this case, the r...

  20. WordPress REST API Vulnerability Abused in Defacement Campaigns

    Research Sucuri, 6 Feb 2017

    WordPress 4.7.2 was released two weeks ago, including a fix for a severe vulnerability in the WordPress REST API. We have been monitoring our WAF network and honeypots closely to see how and when the attackers would try to exploit this i...

  21. RealStatistics Goes TrafficAnalytics

    Research Sucuri, 2 Feb 2017

    In the last few months, our Incident Response Team detected an interesting malicious code that affected a high number of websites. This malware is a variation of the “Realstatistics” campaign described in details in our blog here and alt...

  22. Content Injection Vulnerability in WordPress

    Research Sucuri, 1 Feb 2017

    As part of a vulnerability research project for our Sucuri Firewall (WAF), we have been auditing multiple open source projects looking for security issues. While working on WordPress, we discovered a severe content injection (privilege e...

  23. Joomla admin login bypass - set your UA for full admin access

    Research Sucuri, 1 Feb 2017

    Every day we analyse hundreds of new malicious files. Some of them are simple backdoors, injected iframes, or one liner defacements. Another type of malware, equally interesting, are the ones that interact with authentication interfaces....

  24. Fake Google Analytics tracking code leading to Adware

    Research Sucuri, 31 Jan 2017

    Our Incident Response process makes sure we remove all malicious files and other small pieces of code inserted in good files that could be used to re-gain access to the environment. These pieces of malware could be very easy to detect ba...

  25. Amazon Affiliate Cookie Stuffing

    Research Sucuri, 25 Jan 2017

    We wrote a lot about malware in invisible iframes. This story is about a different type of invisible iframes that hackers may place on your site. As you know, many large ecommerce sites have affiliate programs that allow third-party publ...

  26. Fake bb_press Plugin Redirects to Mobile Pornography

    Research Sucuri, 24 Jan 2017

    When a website is hacked, we often find that attackers have injected multiple backdoors, web shells, and malicious code that allows them to regain access if the original vulnerability is patched. This allows hackers to continue abusing t...

  27. Hooking WordPress Class to Hide Malicious Users

    Research Sucuri, 20 Jan 2017

    When a website is compromised, attackers perform post-exploitation tasks to maintain access to the site for as long as possible. One of these actions is usually the creation of admin users to remotely control the site or automate the cre...

  28. WordPress Performance Optimization Guide

    Research Sucuri, 19 Jan 2017

    Since launching our website performance testing tool we have been getting a lot of questions about how to improve the speed and performance of WordPress websites. Many website owners are not aware how slow their sites are, so we are exci...

  29. Search and Backdoor

    Research Sucuri, 18 Jan 2017

    The ubiquity of “unlimited” shared hosting platforms has incentivized malware in trying to infect as many adjacent website directories as it can to increase its overall surface area. The more infected the area is, the more likely that at...

  30. vBulletin Malware - When Hackers Compete for Backdoor Control

    Research Sucuri, 17 Jan 2017

    A common pattern we see in compromised websites is the presence of backdoors and other malicious code. During Q3 of 2016, we found that 72% of all compromises that we encountered had a PHP-based backdoor hidden within the site. Attackers...

  31. Labs Notes Monthly Recap - Dec/2016

    Research Sucuri, 12 Jan 2017

    Last month there were a number of interesting website hacks being analyzed by our Malware Research Team (MRT) and Incident Response Teams (IRT). The Sucuri Labs website provides technical analysis and industry updates directly from our t...

  32. Camouflage does not have to be advanced to be effective

    Research Sucuri, 12 Jan 2017

    Often times a malware author will try to provide some type of camouflage to their malware’s coding in an effort to disguise an unsuspecting eye from its true intentions. I recently came across an interesting example from a malicious file...

  33. Injection of Unwanted Google AdSense Ads

    Research Sucuri, 10 Jan 2017

    During the last couple of years, it has become quite prevalent for hackers to monetize compromised sites by injecting unwanted ads. They can be pop-up ads triggered when a visitor spends a certain amount of time on an infected page, or a...

  34. Database and Image Tricks in Magento Malware

    Research Sucuri, 10 Jan 2017

    Magento malware that steals details of customer credit cards is a prevalent problem during the last couple of years. We write a lot about various modifications of such malware and the tricks hackers use. When you look back, it’s interest...

  35. Spotlight: How a Social Media Expert Finds Website Security

    Research Sucuri, 6 Jan 2017

    With the new year upon us, it makes sense to reflect on how things have changed. Our Malware Research and Incident Response teams just published their latest report on trends in website security, and in the coming weeks we plan to write ...

  36. Spamming Stopped by Pastebin

    Research Sucuri, 6 Jan 2017

    We wrote multiple times about malware attacks that store their scripts on Pastebin.com and load them either to the server once they break into it or directly to the infected web pages However Pastebin.com can’t be called a reliable hosti...

  37. Hacked Website Report - 2016/Q3

    Research Sucuri, 4 Jan 2017

    Today we are proud to release our quarterly Hacked Website Report for 2016/Q3. This report is based on data collected and analyzed by the Sucuri Remediation Group (RG), which includes the Incident Response Team (IRT) and the Malware Rese...

  38. Release the Prisoners - Rename .Suspected Backdoors

    Research Sucuri, 3 Jan 2017

    When webmasters or hosting companies look for malware, they usually search for encrypted code, encoded payloads, suspicious functions and much more. If they happen to find any of those instances, it’s a common practice to either remove o...

  39. Website Malware Targets Mobile Platforms

    Research Sucuri, 2 Jan 2017

    Navigating the web on a mobile device can be tricky even when you’re browsing clean sites. If hackers are involved, the frustration of a pop-up can turn into the dangerous possibility of harmful mobile malware. The increase in mobile int...

  40. Web shell downloader - simple attempt to avoid detection

    Research Sucuri, 29 Dec 2016

    When dealing with compromised scenarios, our team has to be very thorough to remove all pieces of malware in the infected website. Most of the time attackers don’t inject single bits of code but a variety of malware to increase the chanc...

  41. Not that impressive hack tool

    Research Sucuri, 27 Dec 2016

    There is often a misconception regarding the tools that attackers implement in their malicious activity, and that misconception is that they must be using advanced computer programs to target and exploit other computers. This is not alwa...

  42. New Guide to Fixing Google Blacklist Warnings

    Research Sucuri, 22 Dec 2016

    One of the worst experiences a website owner can have is being blacklisted by Google. If you are one of the 10,000 websites that has been slapped with a big red malware warning, our latest, free DIY guide is for you. Read the Guide to Re...

  43. Malicious script injected to WordPress theme allowing Admin Login Bypass

    Research Sucuri, 22 Dec 2016

    On a daily basis we find different kinds of malware like backdoors, credit card stealers, injected scripts, and phishing pages. While each one of those catches our attention, we recently found an interesting WordPress administration logi...

  44. Malicious JavaScript Injected in Plugin Widget

    Research Sucuri, 20 Dec 2016

    Each and every day the attackers get more clever and exploit new attack vectors. Sucuri Labs recently found a malicious JavaScript hidden in the database of a WordPress website. The malicious code was injected inside a legit widget of th...

  45. Labs Notes Monthly Recap - Nov/2016

    Research Sucuri, 16 Dec 2016

    Time for another monthly recap! If you haven’t seen the other monthly recaps, make sure to check out October and September. Our malware research and incident response teams publish technical content in the Sucuri Labs Notes. The knowledg...

  46. Vbulletin Infections Fighting for Dominance

    Research Sucuri, 15 Dec 2016

    A very common pattern in compromised websites is the presence of backdoors and other malicious codes. Attackers use different techniques and malware to abuse of server resources, distribute spam and at the same time, maintain access to t...

  47. Ask Sucuri: How to Stop Brute Force Attacks?

    Research Sucuri, 14 Dec 2016

    Ask Sucuri: My site is under a brute force attack. What can I do? How can we solve this password guessing problem known as brute forcing? This is a common question we get from users of our WordPress plugin and from the overall community....

  48. Magento Login and Credentials Stealer

    Research Sucuri, 13 Dec 2016

    Lately we’ve been dealing with an increase in attacks against ecommerce platforms. Attackers usually choose this type of solution (like Magento & others) because of the sensitive information on credit cards they can extract, as well as o...

  49. “Play One” Hidden Style Obfuscation

    Research Sucuri, 9 Dec 2016

    For many years, spam injections placed inside legitimate pages remain one of the prevalent types of black hat SEO hacks that we clean. Hackers constantly invent new tricks to make spam blocks invisible to human visitors while indexable b...

  50. Unrestricted Backend Login Backdoor on OpenCart

    Research Sucuri, 6 Dec 2016

    From the attacker’s perspective, creating ways to maintain access to a compromised website is desirable. We call them backdoors. Backdoors can be done in different ways, either by adding fake admin users to the site, or adding pieces of ...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support