HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 5 min ago.
- Hidden iframe Injected into WordPress core file
Research Sucuri, 6 Dec 2016
Injecting malware into core files of CMS installations is one of the techniques attackers use. From the user’s perspective, it is easier to detect and remediate such cases if they are using a File Integrity Monitoring system. On the othe...
- Exploited Script in WordPress Theme Sends Spam
Research Sucuri, 1 Dec 2016
Update 11/03/2017: If you want to learn how to secure WordPress, you can read all about it in our new guide. As WordPress continues to grow in popularity, so does its library. New and experienced developers are creating themes and plugin...
- Image defacement hides content from search engines
Research Sucuri, 1 Dec 2016
Website defacement is still a big issue for various website owners. It directly impacts on your online presence / visibility and as a consequence, it may get your website flagged as “Hacked” by different search engines. Recently, our tea...
- Ask Sucuri: Can Your cPanel Page Be Maliciously Redirected?
Research Sucuri, 29 Nov 2016
Many webmasters may not be aware that hackers are able to maliciously redirect cPanel pages. The specific tactic we describe in this article is unique. Included are recommendations to prevent it, along with other suspicious issues, throu...
- Spotlight: How StreetHunters Fixed a Website Hack
Research Sucuri, 25 Nov 2016
Two years ago, we started compiling reviews from Sucuri customers. Today we have over 60 case studies, most of them from web developers and designers. Interestingly enough, we also have a lot of case studies from photographers who run th...
- Malware DB Injection called via theme file
Research Sucuri, 24 Nov 2016
Attackers use different techniques to distribute SPAM in a compromised website. Most of the time they choose the file structure to inject the malicious code as it’s a more practical approach. There are exceptions to this case though, and...
- Malicious Redirect Injected in Magento One Page Checkout
Research Sucuri, 23 Nov 2016
With the holiday season around the corner, ecommerce sites are very valuable to website owners and equally attractive to attackers. Hackers have been targeting Magento installations in order to steal sensitive information like credit car...
- Website Spam Infection via Zip File Upload
Research Sucuri, 21 Nov 2016
Since the beginning of November we’ve been cleaning many sites infected with the same SEO spam malware. The malware creates doorways for hundreds of random trending keywords - from news to porn. For its templates, it uses mobile pages of...
- Malware Targets Mobile Platforms
Research Sucuri, 17 Nov 2016
With the increase of mobile internet browsing, attackers have adapted their techniques to target such platforms and distribute SPAM & malware to these devices. Our free online scanner SiteCheck is tailored to emulate different Mobile Use...
- Cloned Spam Sites in Subdirectories
Research Sucuri, 15 Nov 2016
In a recent post, we covered how attackers were abusing server resources to create WordPress sites in subdirectories and distribute spam. By adding a complete WordPress CMS installation into a directory and using the victim’s database st...
- Multiple UNIX users symbolic link injector
Research Sucuri, 15 Nov 2016
Recently we found a very interesting malware that injects symbolic links in each and every Linux/UNIX home folder. Once the website is infected, it uses the following code to avoid detection from search engine agents and can be executed ...
- New Guide on How to Fix Hacked Joomla! Sites
Research Sucuri, 11 Nov 2016
Joomla! is one of the most popular open-source content management systems (CMS) on the market, powering a large percentage of websites on the internet today. For that reason, we are glad that our team includes a former contributor who he...
- Malicious routine stealing WordPress credentials in the wild
Research Sucuri, 11 Nov 2016
From the hacker’s perspective, maintaining access to a compromised website for as long as possible, is ideal. One way to achieve this goal, is by stealing user’s credentials. This method also could provide the chance to spread the attack...
- New XM1RPC SEO Spam and Backdoor Campaign
Research Sucuri, 8 Nov 2016
We have been monitoring a new campaign specifically targeting WordPress sites, using hundreds of them for SEO spam distribution. We call it the XM1RPC campaign due to the common backdoor used across all of the compromised sites. The file...
- Labs Notes Monthly Recap - Oct/2016
Research Sucuri, 4 Nov 2016
In our September Labs Notes Recap, we listed recent discoveries made by our Incident Response and Malware Research Teams. These monthly recaps serve to bridge the gap between our blog and the ongoing analysis performed by Sucuri Labs. Fo...
- New version of Magento Credit Card stealer in the wild
Research Sucuri, 3 Nov 2016
Hacking into Magento sites and injecting code to steal payment information is very profitable and it’s the biggest trend we are seeing in 2016. It is interesting enough to notice that the same group is being responsible for several attac...
- Spotlight: How Big Spring Secures Joomla!
Research Sucuri, 2 Nov 2016
Big Spring Web Development understands the responsibility to their clients extends beyond creating a functional and attractive website. Security and stability are critical components of any online presence. The company is one of only a s...
- Learning From Buggy WordPress Wp-login Malware
Research Sucuri, 31 Oct 2016
When a site gets hacked, the attack doesn’t end with the malicious payload or spam content. Hackers know that most website administrators will clean up the infection and look no further. Many go on to patch vulnerable software, change th...
- WordPress Theme Mailing Script being exploited in the wild
Research Sucuri, 31 Oct 2016
A few weeks ago, we posted a lab notes describing a good theme file being exploited by attackers to send mass-mailing SPAM (http://labs.sucuri.net/?note=2016/08/15 0:00). Upon further investigation, we identified that attackers have been...
- Joomla Exploits in the Wild Against CVE-2016-8870 and CVE-2016-8869
Research Sucuri, 28 Oct 2016
Exactly 3 days ago, the Joomla team issued a patch for a high-severity vulnerability that allows remote users to create accounts and increase their privileges on any Joomla site. Both issues combined give the attackers enough power to ea...
- Malicious WordPress Subdirectory Installs For SEO Spam
Research Sucuri, 25 Oct 2016
Remediating over 500 infected sites per day, we see attacks executed at varying levels of complexity. The tactics attackers use to compromise a site provide insight into their motives. Some write elegant code and cover their trails caref...
- Malicious Redirections on Disabled Sites
Research Sucuri, 25 Oct 2016
It’s quite common for attackers to compromise your website and make use of it for their phishing campaigns. The most typical method they use is to simply place redirects throughout your site or simply upload entire phishing folders so th...
- Backdoor abusing of PHP tricks
Research Sucuri, 24 Oct 2016
During an incident response process, we found a very interesting malicious code abusing some PHP tricks. Attackers placed the malware at the end of a WordPress core file ‘./wp-includes/pomo/entry.php’ : $data=file_get_contents("php://inp...
- Backdoors abusing of spaces
Research Sucuri, 21 Oct 2016
Lately we’ve seen more backdoors that have some specific characteristics, like using several spaces between the code and processing information coming from POST requests. Attackers use the “spacing” technique to avoid visual detection in...
- Session Stealer Script on OpenCart CMS
Research Sucuri, 19 Oct 2016
With so many open-source ecommerce platforms available in the market, creating an online shop is as easy as ABC. In less than five minutes you can set up your very own online storefront and offer physical and digital products for sale. I...
- Magento Credit Card Swiper Exports to Image
Research Sucuri, 17 Oct 2016
Over the past year we have seen a rash of credit card swipers in Magento and other ecommerce-based websites. In fact, we have been finding new variants nearly every week. It is no surprise that ecommerce sites are lucrative for attackers...
- WP Marketplace Attack in the Wild
Research Sucuri, 17 Oct 2016
A few days ago, colleagues from White Fir Design disclosed an arbitrary file upload vulnerability in the WP Marketplace plugin and helped remove it from the official repository (at least until a patched version becomes available). They m...
- Ask Sucuri: Is My Website Hacked?
Research Sucuri, 11 Oct 2016
Having your website hacked can be a devastating experience for any website owner. Unfortunately, many website owners rarely know they are infected until days, if not weeks, after the compromise has occurred. Their notification comes in t...
- Mage.js CC Stealer. The Database Version.
Research Sucuri, 7 Oct 2016
Every day we find many Magento credit card stealers injected into different files: modules, core files, themes. Magento database is not an an exception. For example, this credit card stealer was found in the core_config_data table. The o...
- WordPress Hack Modifies Core Files to Share Spam
Research Sucuri, 4 Oct 2016
One of the worst feelings a website owner can experience is discovering that your site has been hacked. Without proper security measures in place, even website owners with the best intentions can lose control of their website. When hacke...
- Targeting mobile devices the easy way
Research Sucuri, 29 Sep 2016
With the outburst of mobile-only malware, we’re seeing a lot of mobile-devices targeted campaigns in last years. There are lot of ways how to make sure that the malware / redirect will be activated only on such a device, including mobile...
- SSH Brute Force Compromises Leading to DDoS
Research Sucuri, 28 Sep 2016
A few weeks ago we ran an experiment to see how long it would take for some IPv4-only and IPv6-only servers to be compromised via SSH brute force attacks. We configured five cloud servers on Linode and Digital Ocean with the root passwor...
- Hacked Website Report - 2016/Q2
Research Sucuri, 21 Sep 2016
Today we’re releasing our quarterly Hacked Website Report for 2016/Q2. The data in this report is based on compromised websites we worked on, with insights and analysis performed by our Incident Response Team (IRT) and Malware Research T...
- Hijacking PayPal Donations
Research Sucuri, 21 Sep 2016
Recently we wrote about how hackers hijacked payment process on an ecommerce site and redirected customers to a fake checkout page on a third-party site. This sort of attacks is not limited to online stores. Even non-commercial sites may...
- Hacking WordPress Sites on Shared Servers
Research Sucuri, 19 Sep 2016
A website is only as safe as the weakest link on its shared server. Once a hacker gains access to one site on the server, they can easily infect other sites that share the same server permissions. This is called cross-site contamination....
- New Guide on How to Fix Hacked WordPress Sites
Research Sucuri, 16 Sep 2016
Our involvement in WordPress security has always been a core part of our mission here at Sucuri. We have teams who actively lend advice on WordPress support forums to hacked webmasters. We’ve taken a leadership role by creating sections ...
- Drupal Database WebShell
Research Sucuri, 13 Sep 2016
Some people are unfamiliar with the Drupal CMS, it doesn’t enjoy the popularity that some others do like WordPress and Joomla, but it’s a powerful CMS none the less. Compared to the way WordPress is structured, Drupal is a big monster! T...
- Cleaning the Wp-Page Pharma Hack in WordPress
Research Sucuri, 6 Sep 2016
Pharma hacks are common website infections categorized under SEO spam. With pharma hacks, the attacker exploits vulnerable websites to distribute pharmaceutical content to search engines and the sites visitors. Symptoms of a pharma hack ...
- Joomla Backdoor Hidden in Plain Sight
Research Sucuri, 31 Aug 2016
In order to avoid detection and maintain access to compromised websites, attackers use different techniques to hide their malicious code. During our cleanup investigation we identified an interesting malicious code that pretended to be a...
- And the next time, go upload a shell to your gramma’s website!
Research Sucuri, 24 Aug 2016
During an incident response process performed in our client’s website, one of our analysts found a very interesting web shell. Our tools detected a suspicious file called “./v8.php” and after some time decoding it, we found out that it w...
- Spotlight: How WebMechanix Provides Client Site Security
Research Sucuri, 19 Aug 2016
WebMechanix is a full-service digital marketing agency focused on managing the online presences of over 100 web properties . In 2009, when WebMechanix was founded, managing websites was a bit less stressful. For website administrators, s...
- Undeletable Doorway. Kind of.
Research Sucuri, 18 Aug 2016
Recently we cleaned a site that had a malicious wp-page.php file at the root of the WordPress site. It was responsible for pharma spam doorways created on this site. The file was quickly located and deleted. To our surprise, when we load...
- Why selling Windows keys in your blog is not a matter of choice
Research Sucuri, 17 Aug 2016
Sharing spam content and getting blacklisted is not a matter of choice when a website is hacked, these are just some of the consequences when attackers compromise a blog/website and that is why it is so important to have security measure...
- SQL Injection Vulnerability in Ninja Forms
Research Sucuri, 16 Aug 2016
As part of our regular research audits for our Sucuri Firewall, we discovered an SQL Injection vulnerability affecting the Ninja Forms plugin for WordPress, currently installed on 600,000+ websites. Vulnerability Disclosure Timeline: Aug...
- Mass Mailing SPAM From a Good File
Research Sucuri, 15 Aug 2016
We often find code that is developed with good intent but the security aspects of it are not always taken into consideration. During a routine cleanup investigation we found a php script in a theme that used mail capabilities without any...
- Fake WordPress Installs and Sunglasses Spam
Research Sucuri, 9 Aug 2016
Spammers are constantly looking for ways make use of resources of hacked sites in their black hat SEO schemes. In most cases, spam injections and doorway script are quite hard to detect but in this example attackers didn’t worry much abo...
- Spotlight - How Cart66 Maintains Security for Ecommerce
Research Sucuri, 5 Aug 2016
Cart66 offers a comprehensive plugin solution for WordPress shop owners. With a unique suite of services, intuitive features, and essential security components, Cart66 provides everything you need to operate a PCI compliant online store....
- A Plugin’s Expired Domain Poses a Security Threat to Websites
Research Sucuri, 3 Aug 2016
Do you keep all of your website software (including third-party themes, plugins, and components) up to date? You should! We always recommend this to our clients and readers. Applying updates quickly will make sure that you replace any vu...
- Fake FreeDNS Used to Redirect Traffic to Malicious Sites
Research Sucuri, 29 Jul 2016
During the last couple of days, we performed a few similar cleanup requests where sites occasionally redirected visitors to malicious sites that displayed ads, spam, and malicious downloads. One of our security analysts, Andrey Kucherov,...
- JScript ASP.NET Backdoor
Research Sucuri, 29 Jul 2016
Backdoors can be simple and powerful at the same time. They’re also very common to be seen along with any kind of infection so that an attacker can get unauthorized access to the server and, although you try to clean the whole malicious ...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.