Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 1 min ago.

  1. Magento Platform Targeted By Credit Card Scrapers

    Research Sucuri, 24 Jun 2015

    We’ve been writing a lot about ecommerce hacks and PCI Compliance recently. The more people buy things online, the more of an issue this will be come and the more important it will be to talk about it. We live in an online world where a ...

  2. Websites Hacked Via Website Backups

    Research Sucuri, 23 Jun 2015

    For the past few months, we’ve spent a good deal of time talking about backups. This is for good reason: backups are your safety net when things go wrong. Interestingly enough though, they are often the forgotten pillar of security. We s...

  3. 10 Tips to Improve Your Website Security

    Research Sucuri, 16 Jun 2015

    In recent years there has been a proliferation of great tools and services in the web development space. Content management systems (CMS) like WordPress, Joomla!, Drupal and so many others, allow business owners to quickly and efficientl...

  4. Security Advisory: Object Injection Vulnerability in WooCommerce

    Research Sucuri, 11 Jun 2015

    During a routine audit for our WAF, we discovered a dangerous Object Injection vulnerability in WooCommerce which could, in certain contexts, be used by an attacker to download any file on the vulnerable server. Are You At Risk? The vuln...

  5. SweetCAPTCHA Service Used to Distribute Adware

    Research Sucuri, 9 Jun 2015

    SweetCaptcha is a free CAPTCHA service that offers to match “sweet” images instead of making you recognize distorted digits and characters. It has integrations with many website platforms including; pure PHP, WordPress (10,000+ plugin in...

  6. Your Website’s Been Hacked But No Signs of Infection

    Research Sucuri, 2 Jun 2015

    Imagine for a moment you suspect that your website has been hacked. Something is off, but you feel as if you are missing what that something is. Paranoia can grip you once you recognize that something is not right. As humans we need clos...

  7. Website Security: How Do Websites Get Hacked?

    Research Sucuri, 24 May 2015

    In 2014, the total number of websites on the internet reached 1 billion . Today it’s hovering somewhere in the neighborhood of 944 million due to websites going inactive, and it is expected to normalize again at 1 billion sometime in 201...

  8. Fake jQuery Scripts in Nulled WordPress Plugins

    Research Sucuri, 22 May 2015

    We recently investigated some random redirects on a WordPress website that would only happen to certain visitors. Traffic analysis showed us that it was not a server-side redirect, rather it happened due to some script loaded by the web ...

  9. JetPack and TwentyFifteen Vulnerable to DOM-based XSS

    Research Sucuri, 6 May 2015

    Any WordPress Plugin or theme that leverages the genericons package is vulnerable to a DOM-based Cross-Site Scripting (XSS) vulnerability due to an insecure file included with genericons . So far, the JetPack plugin (reported to have ove...

  10. Hacked Websites Redirect to Bitcoin

    Research Sucuri, 4 May 2015

    Recently, we began to notice that some hacked websites were redirecting traffic from certain browsers to the BitCoin site, bitcoin.org . What’s going on? Is Bitcoin using black hat SEO? Is their site malicious? As you can see, the hacked...

  11. Critical Persistent XSS 0day in WordPress

    Research Sucuri, 27 Apr 2015

    *Update 2015-04-27*: A patch has been released and made available by the WordPress Core Team in version 4.2.1 - Please update immediately. Yes, you’ve read it right: a critical, unpatched XSS 0day in WordPress’ comment mechanisms was dis...

  12. Security Advisory: XSS Vulnerability Affecting Multiple WordPress Plugins

    Research Sucuri, 20 Apr 2015

    Multiple WordPress Plugins are vulnerable to Cross-site Scripting (XSS) due to the misuse of the add_query_arg() and remove_query_arg() functions. These are popular functions used by developers to modify and add query strings to URLs wit...

  13. Impacts of a Hack on a Magento Ecommerce Website

    Research Sucuri, 15 Apr 2015

    Recently we wrote about the impacts of a hacked website and how it is important to give website visitors a safe online experience. In this post, I’ll show you how a hacked website results in almost immediate loss of money . We’re not tal...

  14. FBI Public Service Annoucement: Defacements Exploiting WordPress Vulnerabilities

    Research Sucuri, 8 Apr 2015

    The US Federal Bureau of Investigation (FBI) just released a public service announcement (PSA) to the public about a large number of websites being exploited and compromised through WordPress plugin vulnerabilities: Continuous Web site d...

  15. Security Advisory: Persistent XSS in WP-Super-Cache

    Research Sucuri, 7 Apr 2015

    During a routine audit for our Website Firewall (WAF), we discovered a dangerous persistent XSS vulnerability affecting the very popular WP-Super-Cache plugin (more than a million active installs according to WordPress.org). The security...

  16. Website Malware - The SWF iFrame Injector Evolves

    Research Sucuri, 2 Apr 2015

    Last year, we released a post about a malware injector found in an Adobe Flash (.swf) file. In that post, we showed how a SWF file is used to inject an invisible, malicious iFrame. It appears that the author of that Flash malware continu...

  17. WordPress Malware Causes Psuedo-Darkleech Infection

    Research Sucuri, 26 Mar 2015

    Darkleech is a nasty malware infection that infects web servers at the root level. It use malicious Apache modules to insert hidden iframes with certain responses. It’s difficult to detect because the malware is only active when both the...

  18. The Impacts of a Hacked Website

    Research Sucuri, 19 Mar 2015

    Today, with the proliferation of open-source technologies like WordPress, Joomla and other Content Management Systems (CMS) people around the world are able to quickly establish a virtual presence with little to no cost. In the process h...

  19. Understanding WordPress Plugin Vulnerabilities

    Research Sucuri, 17 Mar 2015

    When WordPress vulnerabilities are disclosed in plugins, there are often many questions. Some are minor issues, some are more relevant, while others are what we’d categorize as noise. How are you supposed to make sense of all this? To he...

  20. Inverted WordPress Trojan

    Research Sucuri, 11 Mar 2015

    A trojan (or trojan horse) is software that does (or pretends to be doing) something useful but also contains a secret malicious payload that inconspicuously does something bad. In WordPress, typical trojans are plugins and themes (usual...

  21. Security Advisory: MainWP-Child WordPress Plugin

    Research Sucuri, 10 Mar 2015

    During a routine audit of our Website Firewall (WAF), we found a critical vulnerability affecting the popular MainWP Child WordPress plugin. According to WordPress.org, it is installed on more than 90,000 WordPress websites as as remote ...

  22. Malware Cleanup to Arbitrary File Upload in Gravity Forms

    Research Sucuri, 26 Feb 2015

    During our regular cleanup process we came across a reinfection case that caught our attention. This particular environment didn’t have anything special or fancy, it was an updated WordPress installation and had 3 out-of-date plugins; th...

  23. Why Websites Get Hacked

    Research Sucuri, 26 Feb 2015

    I spend a good amount of time engaging with website owners across a broad spectrum of businesses. Interestingly enough, unless I’m talking large enterprise, there is a common question that often comes up: Why would anyone ever hack my we...

  24. Security Advisory - WP-Slimstat 3.9.5 and Lower

    Research Sucuri, 25 Feb 2015

    WP-Slimstat users should update as soon as possible! During a routine audit for our WAF, we discovered a security bug that an attacker could, by breaking the plugin’s weak “secret” key, use to perform a SQL Injection attack against the t...

  25. Analysis of the Fancybox-For-WordPress Vulnerability

    Research Sucuri, 16 Feb 2015

    We were alerted last week of a malware outbreak affecting WordPress sites using version 3.0.2 and lower of the fancybox-for-wordpress plugin. As announced, here are some of the details explaining how attackers could use this vulnerabilit...

  26. Analyzing Malicious Redirects in the IP.Board CMS

    Research Sucuri, 10 Feb 2015

    Although the majority of our posts describe WordPress and Joomla attacks (no wonder, given their market-share), there are still attacks that target smaller CMS’s and we help clean all kinds of sites. This post will be about conditional r...

  27. Zero-day in the Fancybox-for-WordPress Plugin

    Research Sucuri, 4 Feb 2015

    Update : We posted an analysis of the vulnerability following this post. Our research team was alerted to a possible malware outbreak affecting many WordPress websites. All the infections had a similar malicious iframe from “ 203koko ” i...

  28. Advisory - Dangerous “nonce” Leak in UpdraftPlus

    Research Sucuri, 3 Feb 2015

    If you’re a user of the UpdraftPlus plugin for WordPress, now is the time to update. During a routine audit of our Website Firewall (WAF), we detected a “nonce” leak vulnerability affecting the UpdraftPlus WordPress plugin. The vulnerabi...

  29. Bogus Mobile-Shortcuts WordPress Plugin Injects SEO Spam

    Research Sucuri, 30 Jan 2015

    Here at Sucuri we see countless cases of SEO spam where a website is compromised in order to spread pharmaceutical advertisements or backlinks to sites selling luxury goods. Most of the time this involves injecting hundreds of spam links...

  30. DDoS from China - Facebook, WordPress and Twitter Users Receiving Sucuri Error Pages

    Research Sucuri, 27 Jan 2015

    Over the past few weeks our Security Operation Center (SOC) has been seeing some unique and very suspicious requests to some of our servers. At first we thought it was a Distributed Denial of Service (DDoS) attack, mainly due to the high...

  31. Security Advisory - Vulnerabilities in Pagelines for WordPress

    Research Sucuri, 21 Jan 2015

    Users of both the Pagelines and Platform themes should update as soon as possible. During a routine audit for our WAF, we found two dangerous issues: A Privilege Escalation vulnerability affecting both themes and a Remote Code Execution ...

  32. AdSense Abused with Malvertising Campaign

    Research Sucuri, 14 Jan 2015

    Last weekend we noticed a large number of requests to scan websites for malware because they randomly redirected to some “magazine” websites. Most of them mentioned the lemode-mgz .com site. In all cases, the symptoms were the same. Some...

  33. Website Backdoors Leverage the Pastebin Service

    Research Sucuri, 6 Jan 2015

    We continue our series of posts about hacker attacks that exploit a vulnerability in older versions of the popular RevSlider plugin. In this post we’ll show you a different backdoor variant that abuses the legitimate Pastebin.com service...

  34. 2014 Website Defacements

    Research Sucuri, 1 Jan 2015

    When a website has been defaced, it is often the most visual and obvious hack that a website can suffer from. They also come parceled with their own exquisite sense of dread. Nothing gives that gut-wrenching feeling of “I’ve been hacked”...

  35. WP Symposium - Zero Day Vulnerability Dangers

    Research Sucuri, 31 Dec 2014

    Our friends at SpiderLabs released a blog post today talking about the latest WP Symposium file upload vulnerability, and the attacks they have been seeing in the wild. This specific vulnerability was disclosed publicly Dec 11th, and att...

  36. Analyzing The WordPress SoakSoak Favicon Backdoor

    Research Sucuri, 29 Dec 2014

    This post is a dissection of one of a few backdoor variations hackers are uploading via the RevSlider security hole. We also provide webmasters a complete mitigation plan. In the previous post we described how hackers upload a ZIP file w...

  37. RevSlider MalFrames - SoakSoak

    Research Sucuri, 28 Dec 2014

    The RevSlider SoakSoak malware campaign started with the soaksoak.ru domain (hence the name). However, since thelast 2 weeks, it has mutated and used different domains as the initial malware intermediary. This is the full list so far: so...

  38. New Malware Campaign - WPcache-Blogger - Affects Thousands more WordPress Websites via RevSlider

    Research Sucuri, 24 Dec 2014

    If SoakSoak wasn’t enough, we are starting to see a new malware campaign leveraging the RevSlider vulnerability and compromising thousands of WordPress sites in the last few days. Unlike SoakSoak, it’s comprised of 3 distinct malframes -...

  39. SoakSoak: Payload Analysis - Evolution of Compromised Sites - IE 11

    Research Sucuri, 16 Dec 2014

    Thousands of WordPress sites have been hit by the SoakSoak attack lately. At this moment we know quite a lot about it; it uses the RevSlider vulnerability as a point of penetration, then uploads a backdoor and infects all websites that s...

  40. RevSlider Vulnerability Leads To Massive WordPress SoakSoak Compromise

    Research Sucuri, 15 Dec 2014

    Yesterday we disclosed a large malware campaign targeting and compromising over 100,000 WordPress sites, and growing by the hour. It was named SoakSoak due to the first domain used in the malware redirection path (soaksoak.ru). After a b...

  41. SoakSoak Malware Compromises 100,000+ WordPress Websites

    Research Sucuri, 14 Dec 2014

    This Sunday has started with a bang. Google has blacklisted over 11,000 domains with this latest malware campaign from SoakSoak.ru : Our analysis is showing impacts in the order of 100’s of thousands of WordPress specific websites. We ca...

  42. Malvertising on a Website Without Ads

    Research Sucuri, 12 Dec 2014

    When you first configure your website, whether it be WordPress, Joomla, Drupal, or any other flavor of the month, it is often in its purest state. Unless ofcourse the server was previously compromised, which in it of itself is another co...

  43. Critical Vulnerability Affecting HD FLV Player

    Research Sucuri, 10 Dec 2014

    We’ve been notified of a critical vulnerability affecting the HD FLV Player plugin for Joomla, WordPress and custom websites. It was silently patched on Joomla and WordPress, leaving the custom website version vulnerable. Furthermore, we...

  44. IIS, Compromised GoDaddy Servers, and Cyber Monday Spam

    Research Sucuri, 8 Dec 2014

    While doing an analysis of one black-hat SEO doorway on a hacked site, I noticed that it linked to many similar doorways on other websites, and all those websites were on IIS servers. When I see these patterns, I try to dig deeper and fi...

  45. Leveraging the WordPress Platform for SPAM

    Research Sucuri, 5 Dec 2014

    We’ve all seen WordPress comment and pingback spam, but thanks to strict moderation regimes and brilliant WordPress plugins that focus strictly on SPAM comments, comment spam isn’t a major problem for most websites these days. I have see...

  46. Security Advisory - High Severity- WordPress Download Manager

    Research Sucuri, 4 Dec 2014

    If you’re using the popular WP Download Manager plugin (around 850,000 downloads), you should update right away. During a routine audit for our Website Firewall (WAF), we found a dangerous remote code execution (RCE) and remote file incl...

  47. Security Advisory - High Severity - InfiniteWP Client WordPress plugin

    Research Sucuri, 2 Dec 2014

    If you’re using the InfiniteWP WordPress Client plugin to manage your website, now is a good time to update. While doing a routine audit of our Website Firewall product, we discovered a vulnerability in the plugin that could be used by a...

  48. JoomDonation Compromised

    Research Sucuri, 26 Nov 2014

    We are receiving reports from many users of the popular JoomDonation platform that they received a very scary email from someone that supposedly hacked into JoomDonation. The emails went to the registered accounts and contained the full ...

  49. Website Malware Removal: Phishing

    Research Sucuri, 21 Nov 2014

    As we continue on our Malware Removal series we turn our attention to the increasing threat of Phishing infections. Just like a fisherman casts and reels with his fishing rod, a “phisher-man” will try their luck baiting users with fake p...

  50. Security Advisory - High severity - WP-Statistics WordPress Plugin

    Research Sucuri, 20 Nov 2014

    If you’re using the WP-Statistics WordPress plugin on your website, now is the time to update. While doing a routine audit for our Website Firewall product, we discovered a few vulnerabilities in the plugin that could be used by a malici...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support