HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,887 reports kept since 2009. Updated automatically every 10 minutes. Last checked 7 min ago.
- Critical Vulnerability Affecting HD FLV Player
Research Sucuri, 10 Dec 2014
We’ve been notified of a critical vulnerability affecting the HD FLV Player plugin for Joomla, WordPress and custom websites. It was silently patched on Joomla and WordPress, leaving the custom website version vulnerable. Furthermore, we...
- IIS, Compromised GoDaddy Servers, and Cyber Monday Spam
Research Sucuri, 8 Dec 2014
While doing an analysis of one black-hat SEO doorway on a hacked site, I noticed that it linked to many similar doorways on other websites, and all those websites were on IIS servers. When I see these patterns, I try to dig deeper and fi...
- Leveraging the WordPress Platform for SPAM
Research Sucuri, 5 Dec 2014
We’ve all seen WordPress comment and pingback spam, but thanks to strict moderation regimes and brilliant WordPress plugins that focus strictly on SPAM comments, comment spam isn’t a major problem for most websites these days. I have see...
- Security Advisory - High Severity- WordPress Download Manager
Research Sucuri, 4 Dec 2014
If you’re using the popular WP Download Manager plugin (around 850,000 downloads), you should update right away. During a routine audit for our Website Firewall (WAF), we found a dangerous remote code execution (RCE) and remote file incl...
- Security Advisory - High Severity - InfiniteWP Client WordPress plugin
Research Sucuri, 2 Dec 2014
If you’re using the InfiniteWP WordPress Client plugin to manage your website, now is a good time to update. While doing a routine audit of our Website Firewall product, we discovered a vulnerability in the plugin that could be used by a...
- JoomDonation Compromised
Research Sucuri, 26 Nov 2014
We are receiving reports from many users of the popular JoomDonation platform that they received a very scary email from someone that supposedly hacked into JoomDonation. The emails went to the registered accounts and contained the full ...
- Website Malware Removal: Phishing
Research Sucuri, 21 Nov 2014
As we continue on our Malware Removal series we turn our attention to the increasing threat of Phishing infections. Just like a fisherman casts and reels with his fishing rod, a “phisher-man” will try their luck baiting users with fake p...
- Security Advisory - High severity - WP-Statistics WordPress Plugin
Research Sucuri, 20 Nov 2014
If you’re using the WP-Statistics WordPress plugin on your website, now is the time to update. While doing a routine audit for our Website Firewall product, we discovered a few vulnerabilities in the plugin that could be used by a malici...
- RSS Reveals Malware Injections
Research Sucuri, 19 Nov 2014
There are multiple different ways to detect invisible malware on a website: You can scrutinize the HTML code of web pages. Use external scanners like SiteCheck or UnmaskParasites. Get alerts from anti-viruses or search engines (both in s...
- The Art of Website Malware Removal - The Basics
Research Sucuri, 14 Nov 2014
When talking about defense against malicious hacks, the attack vector is a common topic for Information Security (InfoSec) professionals. The primary concern is to understand the anatomy of the attack and prevent it from happening again....
- The Psychology Behind Why Websites Get Hacked
Research Sucuri, 12 Nov 2014
It’s an everyday conversation for security professionals that interact with new customers. The one where we have to explain that just because everything seems fine, doesn’t mean that the best security practices shouldn’t be followed, or ...
- The Dangers of Hosted Scripts - Hacked jQuery Timers
Research Sucuri, 10 Nov 2014
Google blacklisted a client’s website claiming that malicious content was being displayed from “forogozoropoto(dot)2waky (dot)com” . A scan didn’t reveal anything suspicious. The next step was to check all third-party scripts on the webs...
- Combat Black Hat SEO Infections with SEO Insights
Research Sucuri, 7 Nov 2014
Black hat SEO spam is the plague of the internet, and the big search engines take it seriously. One of the worst spam tactics on the internet is becoming more common every day - innocent websites hacked, and their best pages begin linkin...
- Malicious iFrame Injector Found in Adobe Flash File (.SWF)
Research Sucuri, 5 Nov 2014
Finding malware in Adobe Flash files (.swf) is nothing new, but it usually affects personal computers, not servers. Typically, a hidden iframe is used to drop a binary browser exploit with .SWF files, infecting the client machine. This t...
- Security Advisory - Medium Severity - WP eCommerce WordPress Plugin
Research Sucuri, 31 Oct 2014
If you’re using the popular WP eCommerce WordPress plugin (2,900,000 downloads), you should update it right away. During a routine audit for our Website Firewall (WAF), we found a dangerous vulnerability that could be used by a malicious...
- Drupal Warns - Every Drupal 7 Website Compromised Unless Patched
Research Sucuri, 29 Oct 2014
The Drupal team released an update to a critical SQL Injection vulnerability a few weeks ago and urged all their users to update or patch their sites immediately. If your site has been compromised you can use our free guide to fixing Dru...
- Threat Introduced via Browser Extensions
Research Sucuri, 29 Oct 2014
We love investigating unusual hacks. There are so many ways to compromise a website, but often it’s the same thing. When we see malicious code on web pages, our usual suspects are: Vulnerabilities in website software Trojanized software ...
- ASP Backdoors? Sure! It’s not just about PHP
Research Sucuri, 27 Oct 2014
I recently came to the realization that it might appear that we’re partial to PHP and WordPress. This realization has brought about an overwhelming need to correct that perception. While they do make up an interesting percentage, there a...
- Google Blacklists Bit.ly
Research Sucuri, 25 Oct 2014
If you ever shortened a URL using bit.ly or if you use it anywhere, be aware that Google recently blacklisted all bit.ly pages through its Safe Browsing program. It means that anyone using Chrome, Firefox or Safari will get a nasty The s...
- Popular Brazilian Site “Porta dos Fundos” Hacked
Research Sucuri, 24 Oct 2014
A very well known Brazilian comedy site, “Porta dos Fundos,” was recently hacked and is pushing malware (drive-by-download) via a malicious Flash executable, as you can see from our Sitecheck results: If you do not want the joke to be on...
- Manipulating WordPress Plugin Functions to Inject Malware
Research Sucuri, 23 Oct 2014
Most authors of website malware usually rely on the same tricks, making it easy for malware researchers to spot obfuscated code, random files that don’t belong, and malicious lines injected at the top of a file. However, it can become di...
- Chinese Doorway Spam - P2
Research Sucuri, 21 Oct 2014
We are seeing an increasing number of hacked sited with Chinese doorways promoting various fake merchandises (from Louis Vuitton handbags to NFL jerseys and Canada goose jackets). Those doorways target both Western web searches and the C...
- Drupal SQL Injection Attempts in the Wild
Research Sucuri, 17 Oct 2014
Update (2014/10/29): The Drupal team just released a Public Service Announcement, confirming what we are seeing (mass compromise of Drupal sites). We’ve released a new post with recovery information and a guide to cleaning Drupal hacks i...
- WordPress Websites Continue to Get Hacked via MailPoet Plugin Vulnerability
Research Sucuri, 9 Oct 2014
The popular Mailpoet(wysija-newsletters) WordPress plugin had a serious file upload vulnerability a few months back, allowing an attacker to upload files to vulnerable sites. This issue was disclosed months ago and the MailPoet team patc...
- Phishing with Help from Compromised WordPress Sites
Research Sucuri, 6 Oct 2014
We get thousands of spam and phishing emails daily. We use good spam filters (along with Gmail) and that greatly reduces the noise in our inbox. Today though, one slipped through the crack and showed up in my personal inbox: As I went to...
- Website Security: A Case of SEO Poisoning
Research Sucuri, 2 Oct 2014
There are so many ways your website can be co-opted by hackers for many different reasons, targeting the value created via your SEO is highly attractive. It provides an attacker the opportunity to cheat the system by quickly benefiting f...
- Website Malware - Curious .htaccess Conditional Redirect Case
Research Sucuri, 23 Sep 2014
I really enjoy when I see different types of conditional redirects on compromised sites. They are really hard to detect and always lead to interesting investigations. Take a look at this last one we identified: The curious aspect about i...
- Conditional Malicious iFrame Targeting WordPress Web Sites
Research Sucuri, 19 Sep 2014
We have an email address, labs@sucuri.net where we receive multiple questions a day about various forms of malware. One of the most common questions happen when our Free Security Scanner, SiteCheck, detects a spam injection or a hidden i...
- WordFence WordPress Security Plugin Pushes a Security Update
Research Sucuri, 18 Sep 2014
If you are one of the many users of the WordPress Security Plugin, WordFence, we highly encourage you to update. They recently pushed out a security update that could be affecting your install. It is important to note however that what i...
- The WordPress Security Plugin Ecosystem
Research Sucuri, 16 Sep 2014
As a child, did you ever play that game where you sit in a circle and one person is responsible for whispering something into one persons ear, and that message gets relayed around the circle? Wasn’t it always funny to see what the final ...
- Website Security - Compromised Website Used To Hack Home Routers
Research Sucuri, 11 Sep 2014
What if we told you that a compromised website has the ability to hack your home router? Yesterday we were notified that a popular newspaper in Brazil (politica.estadao.com.br) was hacked and loading several iframes. These iframes were t...
- Microsoft IIS Web Server - CMD Process Contributing to Website Reinfections
Research Sucuri, 9 Sep 2014
We often spend a lot of time talking about application level malware, but from time to time we do like to dabble in the ever so interesting web server infections as well. It is one of those things that comes with the job. Today, we’re go...
- Slider Revolution Plugin Critical Vulnerability Being Exploited
Research Sucuri, 3 Sep 2014
12.17.2014: See more information on the SoakSoak massive malware outbreak resulting from this vulnerability: RevSlider Vulnerability Leads To Massive WordPress SoakSoak Compromise by Daniel Cid If you need help cleaning a hacked WordPres...
- My WordPress Website Was Hacked
Research Sucuri, 27 Aug 2014
Before you freak out, allow me to clarify. It was one of several honeypots we have running. The honeypots are spread across the most commonly employed hosting companies. From Virtual Private Servers (VPS) to shared environments, to manag...
- Thoughts on WordPress Security and Vulnerabilities
Research Sucuri, 15 Aug 2014
As avid readers of this blog know, we’ve discovered or written about multiple vulnerabilities within the WordPress ecosystem over the last couple of weeks specifically relating to popular plugins. MailPoet and Custom Contact Forms drove ...
- Website Malware: Mobile Redirect to BaDoink Porn App Evolving
Research Sucuri, 12 Aug 2014
Recently, we wrote about a malware redirect causing compromised sites to redirect their visitors to pornographic content (specifically, the BaDoink app). You can read more about what we found by going to our previous blog post. As descri...
- Critical Vulnerability Disclosed on WordPress Custom Contact Forms Plugin
Research Sucuri, 7 Aug 2014
If you’re a using the Custom Contact Forms WordPress plugin, you need to update it right away. During a routine audit for our WAF, we found a critical vulnerability that allows an attacker to download and modify your database remotely (n...
- WordPress and Drupal Core Denial Of Service Vulnerability - Moderately Critical
Research Sucuri, 6 Aug 2014
Both WordPress and Drupal are affected by a DoS (denial of service) vulnerability on the PHP XML parser used by their XMLRPC implementations. The issue lies in the XML entity expansion parser that can cause CPU and memory exhaustion and ...
- Website Security Analysis: A “Simple” Piece of Malware
Research Sucuri, 6 Aug 2014
For regular readers of this blog, there is one constant that pops up over and over: Malware gets more complex. When malware researchers, like myself, unlock new obfuscated code, it’s a signal to the black hats that they need to up their ...
- Yoast and Sucuri Partner to Create a Safer Web
Research Sucuri, 4 Aug 2014
We’re very excited to finally talk about a partnership that’s been in the works for a few months and in light of the serious nature of the Security in the WordPress ecosystem it only makes sense. It also comes at a time where we, as an o...
- Backups - The Forgotten Website Security Pillar
Research Sucuri, 31 Jul 2014
I travel a lot (might actually be an understatement these days), but the travel always revolves around a couple of common threads - website security education and awareness. In these travels, regardless of whether I’m speaking with a Wor...
- New Brute Force Attacks Exploiting XMLRPC in WordPress
Research Sucuri, 25 Jul 2014
Brute force attacks against WordPress have always been very common. In fact, Brute Force attacks against any CMS these days is a common occurrence, what is always interesting however are the tools employed to make it happen. You create a...
- MailPoet Vulnerability Exploited in the Wild - Breaking Thousands of WordPress Sites
Research Sucuri, 23 Jul 2014
A few weeks ago we found and disclosed a serious vulnerability on the MailPoet WordPress Plugin. We urged everyone to upgrade their sites immediately due to the severity of the issue. The vulnerability allowed an attacker to inject anyth...
- Massive Malware Infection Breaking WordPress Sites
Research Sucuri, 22 Jul 2014
Update: We identified the root cause: MailPoet Vulnerability Exploited in the Wild - Breaking Thousands of WordPress Sites. The last few days has brought about a massive influx of broken WordPress websites. What makes it so unique is tha...
- Disclosure: Insecure Nonce Generation in WPtouch
Research Sucuri, 14 Jul 2014
If you use the popular WPtouch plugin (5M+ downloads) on your WordPress website, you should update it immediately. During a routine audit for our WAF, we discovered a very dangerous vulnerability that could potentially allow a user with ...
- Website Malware - Mobile Redirect to BaDoink Porn App
Research Sucuri, 9 Jul 2014
A few weeks ago we reported that we were seeing a huge increase in the number of websites compromised with a hidden redirection to pornographic content. It was a very tricky injection, with the redirection happening only once per day per...
- Ask Sucuri: Who is Logging into My WordPress Site?
Research Sucuri, 3 Jul 2014
Today, we’re going to revisit our Q&A series. If you have any questions about malware, blacklisting, or security in general, send them to us at: info@sucuri.net. For all the “Ask Sucuri” answers, go here. Question: How Do I Know Who is L...
- Remote File Upload Vulnerability in WordPress MailPoet Plugin (wysija-newsletters)
Research Sucuri, 1 Jul 2014
Marc-Alexandre Montpas, from our research team, found a serious security vulnerability in the MailPoet WordPress plugin. This bug allows an attacker to upload any file remotely to the vulnerable website (i.e., no authentication is requir...
- Spam Hack Targets WordPress Core Install Directories
Research Sucuri, 24 Jun 2014
Do you run your website on WordPress? Have you checked the integrity of your core install lately for SPAM like “Google Pharmacy” stores or other fake stores? We have been tracking and analyzing a growing trend in SEO spam, or Search Engi...
- Disclosure: Remote Code Execution Vuln in Disqus
Research Sucuri, 21 Jun 2014
We recently found a security vulnerability in the Disqus Comment System plugin for WordPress. It could, under very specific conditions, allow an attacker to perform arbitrary remote code execution (RCE). In other words, an attacker can d...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.