HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 8 min ago.
- Spotlight: How iThemes Manages Their Website Security
Research Sucuri, 22 Jul 2016
iThemes was one of the first premium theme shops for WordPress. Over the years their focus has expanded to include premium WordPress plugins that help website owners manage and secure their websites. In addition to a suite of plugins and...
- Malicious ShopSearcher Script
Research Sucuri, 22 Jul 2016
We see a strong trend in hacking ecommerce sites in order to hijack payment process and steal customers credit card details. During the last couple of years, we wrote multiple times about attacks that target Magento, OpenCart, PrestaShop...
- Magento One Page checkout being injected by Malicious Redirects
Research Sucuri, 19 Jul 2016
The checkout process is one of the most important steps for any e-commerce business. The user experience during this process will set the tone for the entire interaction and fortunately lead to a successful sale. Because of that fact, at...
- New Realstatistics Attack Vector Compromising Joomla Sites
Research Sucuri, 15 Jul 2016
Nov 2016 Update: If your Joomla site has been hacked, you can follow our guide to fixing it. Read the Guide! Over the past few weeks we’ve seen a large number of Joomla websites compromised with the Realstatistics malware campaign. This ...
- Out-of-Site Drupal Malware
Research Sucuri, 13 Jul 2016
We recently wrote about a Drupal black-hat SEO hack that among other things redirected users coming from Google to botscache[.]com site. It hijacked the bootstrapping process via the session_inc variable in database, then made Drupal loa...
- Realstatistics Malware Campaign Uses Fake Analytics Sites
Research Sucuri, 8 Jul 2016
In this post we’ll show you the tactics employed by the realstatistics malware campaign to make their injections seem less suspicious. The injection looks like this: The URL appears to be a typical statistics/analytics script: both the d...
- Realstatistics Malware Campaign Leads To Ransomware
Research Sucuri, 6 Jul 2016
Our Incident Response Team (IRT) has been tracking a mass infection campaign over the last two weeks ( codenamed “ Realstatistics “). This campaign has compromised thousands of websites built on the Joomla! and WordPress Content Manageme...
- Straightforward Backdoor Installer
Research Sucuri, 4 Jul 2016
Malware uses encryption, obfuscation and other tricks to prevent its detection so that the compromised sites stay infected for as long as possible. Quite often it’s not easy to spot a malicious code even if you see it, especially if you ...
- Spotlight: WPBeginner’s Approach to WordPress Security
Research Sucuri, 1 Jul 2016
WPBeginner offers tutorials, tips, and tricks for WordPress beginners to improve their sites. With over 150K Twitter followers and almost 10 million monthly visitors, the website is undeniably popular. The high-quality content provided b...
- SEO Poisoning on nulled templates
Research Sucuri, 16 Jun 2016
We at Sucuri, always stress the risks associated with using themes, plugins or any add-on downloaded from unofficial sources (Nulled Versions). During our investigation process, we found into a theme, a malicious code being used to promo...
- MiniCMS as a Spam Site Generator
Research Sucuri, 14 Jun 2016
SEO spam is very common for a reason - money. Spammers are paid to promote websites on Google. We deal with lots of SEO spam cases daily. The most common cases are database infections, theme file infections and random spammy html pages. ...
- Blacklist Monitoring for Hackers and Webmasters
Research Sucuri, 9 Jun 2016
An infected site can be efficient for cyber-criminals unless it gets blacklisted. Traffic significantly drops when a URL is on the Google’s Safe Browsing list. And if the hacked site is used for sending out email spam, then the success o...
- Phishers Abuse Hosting Temporary URLs
Research Sucuri, 7 Jun 2016
Recently we told you how hackers use alternative domain names provided by web hosts to make their URLs look less suspicious. This time we’ll show a similar trick used by phishers. Phishing web pages get blacklisted very fast. That’s why ...
- Magento Credit Card Stealer for Braintree Extension
Research Sucuri, 3 Jun 2016
We regularly find and write about malware that steals credit card details from Magento sites because attackers discover new techniques to obtain sensitive data daily. This time, the malicious code is specifically designed for Magento sit...
- WP Mobile Detector Vulnerability Being Exploited in the Wild
Research Sucuri, 2 Jun 2016
***Update: The WP Mobile Detector plugin has been patched to address the vulnerability. Please update as soon as possible. Note that the latest version don’t fully address the issue and we contacted the developer try to fix it correctly ...
- File Uploader in Drupal Database
Research Sucuri, 31 May 2016
It’s very common to see backdoors such as uploaders among site’s files. However, we have seen more often cases where file uploaders, mainly in Drupal websites, are located in the database. Many anti-malware products won’t catch those sin...
- Security Advisory: Stored XSS in Jetpack
Research Sucuri, 27 May 2016
During regular research audits for our Sucuri Firewall (Cloud WAF), we discovered a stored XSS vulnerability affecting the WordPress Jetpack plugin, currently installed on more than a million WordPress sites. The vulnerability can be eas...
- Magento CC stealer adding user’s credentials to the loot
Research Sucuri, 25 May 2016
While analyzing a compromised Magento site, we found another Credit Card (CC) stealer variation. We posted a few times about this type of malware, but this one is a bit different in a way that it also steals the login credentials for the...
- Nulled WordPress Themes: Malvertising and Black Hat SEO
Research Sucuri, 24 May 2016
If you have been following our blog for some time, you know that we regularly warn about risks associated with the use of third-party software on your site. A benign plugin may sneakingly inject ads into your site which cause malvertisin...
- Credit Card Stealer on OpenCart CMS
Research Sucuri, 23 May 2016
We have previously analyzed many Credit Card stealers code, specially targeting the Magento platform: Magento Malware Emails Stolen Credit Card Details to Hackers Magento script stealing credit card details However, this type of maliciou...
- Backdoor in Fake Joomla! Core Files
Research Sucuri, 20 May 2016
We usually write a lot about obfuscation methods on Sucuri Labs and here on the blog. Sometimes we write about free tools to obfuscate your code that aren’t that free and we also have an online tool to help decoding the malware you find....
- Mobile conditional redirect hidden in the database
Research Sucuri, 19 May 2016
We recently found a website that was redirecting mobile users to a third-party site called chickenkiller .com , after further investigation we found that the malware was actually injected into the database, the code was hex encoded t...
- Hacked Website Report - 2016/Q1
Research Sucuri, 18 May 2016
Our Remediation group is comprised of two distinct teams, the Incident Response Team (IRT) and Malware Research Team (MRT). These teams work closely with our customers in an effort to identify and remove website infections to include mal...
- Secure Coding: How to Account for Input Sanitization
Research Sucuri, 17 May 2016
On average, a website leverages around 18-20 different plugins in its structure. These plugins enhance the website’s functionality and in some instances extend the applications core capabilities. It’s great for website owners because the...
- New Wave of the Test0.com/Test5.xyz Redirect Hack
Research Sucuri, 11 May 2016
Last week we described the hack that randomly redirected site visitors either to a parked test0 .com domain or to malicious sites via the default7 .com domain. This week the default7 .com domain went down but the attackers returned with ...
- Hiding Links Behind Punctuation Marks
Research Sucuri, 9 May 2016
In black hat SEO schemes, some links don’t have to have descriptive anchor keywords. For example, if their only purpose is help search engine crawlers discover newly created doorways. But even in such cases, the links should be hidden fr...
- Host’s Alternative Domain Names May Hide Malware
Research Sucuri, 6 May 2016
To make malicious injections look less suspicious, hackers like to use domains that look credible. It may be some typo domain like google-analystisc[.]com instead of google-analytics.com , or correct domain names under a different TLDs, ...
- WordPress Redirect Hack via Test0.com/Default7.com
Research Sucuri, 5 May 2016
Update 9/14/16 : We released a new guide that provides better instructions on how to clean a hacked WordPress site using the Free WordPress security plugin. We’ve been working on a few WordPress sites with the same infection that randoml...
- Security Advisory: Stored XSS in bbPress
Research Sucuri, 4 May 2016
During regular research audits of our Sucuri Firewall, we discovered a Stored XSS vulnerability affecting the bbPress plugin for WordPress which is currently installed on 300,000 live websites - one of them being the popular wordpress.or...
- Credit Card Stealer on osCommerce
Research Sucuri, 28 Apr 2016
We regularly detect malware that targets payment modules on compromised ecommerce websites, mainly on Magento. Recently we’ve stumbled upon the same threat on osCommerce . The malicious code was found inside ./catalog/checkout_confirmati...
- Invisible WordPress Posts
Research Sucuri, 19 Apr 2016
A compromised website is perfect for placing black hat SEO doorways. Usually hackers either create such doorways as static files in deep subdirectories or use a script that dynamically generates doorways and map them to site URLs using v...
- Malicious Cron Jobs
Research Sucuri, 14 Apr 2016
You may remove malware from files and a database, close all security holes, change all passwords, but your site still gets reinfected regularly. It may be because you forgot to clean your crontab. Here’s an example of a malicious cron jo...
- Website Ransomware - CTB-Locker Goes Blockchain
Research Sucuri, 12 Apr 2016
During the last couple of years, website ransomware has become one of the most actively developing types of malware. After infamous fake anti-viruses, this it the second most prominent wave of malware that makes money by directly selling...
- Hacked Websites Redirect to Porn from PDF / DOC Links
Research Sucuri, 29 Mar 2016
We write a lot about various blackhat SEO hacks on this blog and most of you are already familiar with such things as doorways , cloaking and SEO poisoning . This time we’ll tell you about yet another interesting blackhat SEO attack that...
- Ask Sucuri: How Does Sucuri Clean a Website?
Research Sucuri, 24 Mar 2016
Question: How does Sucuri clean hacked websites? What is the process? We clean a lot of websites, ~ 400 / 500, daily during our normal load. To understand how we do it, you have to understand where it all comes from. The biggest challeng...
- Backdoor Evolution: From Eval to Include
Research Sucuri, 24 Mar 2016
There used to be this backdoor that was mainly uploaded via old Gravity Forms vulnerabilities: $a=chr(98).chr(97).chr(115).chr(101).chr(54).chr(52).chr(95).chr(100). chr(101).chr(99).chr(111).chr(100).chr(101); e v a l($a($_REQUEST[sam])...
- Remote WordPress Brute Force Tools
Research Sucuri, 10 Mar 2016
Just a quick reminder: Don’t use common words and easy character combinations as passwords. Your compromised site can be used to hack third-party sites. A real world confirmation of the above two statements sometimes can be found in one ...
- When a WordPress Plugin Goes Bad
Research Sucuri, 4 Mar 2016
Update March 7: The WordPress Directory team investigated and mitigated this issue by disconnecting the wooranker account from all plugins, reverting malicious changes in the CCTM plugin, and changing the version to 0.9.8.9. WordPress sh...
- Behind the Malware - Botnet Analysis
Research Sucuri, 25 Feb 2016
While analyzing our website firewall logs we discovered an old vulnerability being retargeted in RevSlider, a popular WordPress plugin. In 2014 / 2015, this led to massive website compromises. Now it’s being leveraged again in a new atte...
- WordPress Sites Leveraged in Layer 7 DDoS Campaigns
Research Sucuri, 18 Feb 2016
We first disclosed that the WordPress pingback method was being misused to perform massive layer 7 Distributed Denial of Service (DDoS) attacks back in March 2014. The problem being that any WordPress website with the pingback feature en...
- Fake SUPEE-5344 Patch Steals Payment Details
Research Sucuri, 12 Feb 2016
Update 2/17: This post is not about hackers tricking webmasters into installing fake Magento security patch. It’s about malware that pretends to be an applied security patch. In case you don’t know, SUPEE-5344 is an official security pat...
- Seo-moz.com SEO Spam Campaign
Research Sucuri, 10 Feb 2016
Here at Sucuri we handle countless cases of SEO spam. This malware involves a website being compromised in order to spread (mostly pharmaceutical) advertisements by linking visitors to unwanted websites and stuffing spam keywords into th...
- Magento PCI Compliance Issues and Theft Over TLS
Research Sucuri, 6 Feb 2016
With about 30% of the market share, Magento is gradually becoming a “WordPress” of the ecommerce world. Like WordPress, it becomes a major target for hackers due to its popularity. However, in the case of Magento, the main goal that hack...
- Server Security: Import WordPress Events to OSSEC
Research Sucuri, 4 Feb 2016
We leverage OSSEC extensively to help monitor and protect our servers. If you are not familiar with OSSEC, it is an open source Intrusion Detection System (HIDS); it has a powerful correlation and analysis engine that integrates log anal...
- Massive Admedia/Adverting iFrame Infection
Research Sucuri, 1 Feb 2016
This past weekend we registered a spike in WordPress infections where hackers injected encrypted code at the end of all legitimate .js files . The distinguishing features of this malware are: 32 hex digit comments at the beginning and en...
- Ransomware Strikes Websites
Research Sucuri, 12 Jan 2016
Ransomware is one of the most insidious types of malware that one can come across. These infections will encrypt all files on the target computer as well as any hard drives connected to the machine - pictures, videos, text files - you na...
- Speeding up indexing of SPAM files via sitemap.xml
Research Sucuri, 7 Jan 2016
Remember the wave of HTML files infection back in 2015 affecting outdated WordPress sites? Now it came back more powerful, with more files uploaded via a PHP backdoor. We have found large number of created folders in the root folder of a...
- Malicious Pastebin Replacement for jQuery
Research Sucuri, 6 Jan 2016
Website hackers are always changing tactics and borrowing ideas from each other. One of the challenges of website security is staying on top of those threats as they evolve. We wrote in the past about fake jQuery scripts and how hackers ...
- Fake AdWords Domain Advertises USA Immigration Service
Research Sucuri, 5 Jan 2016
You might know Google popular services: Google Ads, AdSense and DoubleClick. You might even know scripts and domains they use. For example, DoubleClick loads scripts from googleads.g.doubleclick.net and AdWords load a conversion tracker ...
- Hiding spam from Ahrefs and Majestic
Research Sucuri, 4 Jan 2016
Many black hat SEO campaigns use cloaking on hacked sites. Malicious scripts only inject spammy content when search engine crawlers request web pages on compromised sites. This time we came across an unusual cloaking condition. We’ve bee...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.