Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 8 min ago.

  1. RSS Reveals Malware Injections

    Research Sucuri, 19 Nov 2014

    There are multiple different ways to detect invisible malware on a website: You can scrutinize the HTML code of web pages. Use external scanners like SiteCheck or UnmaskParasites. Get alerts from anti-viruses or search engines (both in s...

  2. The Art of Website Malware Removal - The Basics

    Research Sucuri, 14 Nov 2014

    When talking about defense against malicious hacks, the attack vector is a common topic for Information Security (InfoSec) professionals. The primary concern is to understand the anatomy of the attack and prevent it from happening again....

  3. The Psychology Behind Why Websites Get Hacked

    Research Sucuri, 12 Nov 2014

    It’s an everyday conversation for security professionals that interact with new customers. The one where we have to explain that just because everything seems fine, doesn’t mean that the best security practices shouldn’t be followed, or ...

  4. The Dangers of Hosted Scripts - Hacked jQuery Timers

    Research Sucuri, 10 Nov 2014

    Google blacklisted a client’s website claiming that malicious content was being displayed from “forogozoropoto(dot)2waky (dot)com” . A scan didn’t reveal anything suspicious. The next step was to check all third-party scripts on the webs...

  5. Combat Black Hat SEO Infections with SEO Insights

    Research Sucuri, 7 Nov 2014

    Black hat SEO spam is the plague of the internet, and the big search engines take it seriously. One of the worst spam tactics on the internet is becoming more common every day - innocent websites hacked, and their best pages begin linkin...

  6. Malicious iFrame Injector Found in Adobe Flash File (.SWF)

    Research Sucuri, 5 Nov 2014

    Finding malware in Adobe Flash files (.swf) is nothing new, but it usually affects personal computers, not servers. Typically, a hidden iframe is used to drop a binary browser exploit with .SWF files, infecting the client machine. This t...

  7. Security Advisory - Medium Severity - WP eCommerce WordPress Plugin

    Research Sucuri, 31 Oct 2014

    If you’re using the popular WP eCommerce WordPress plugin (2,900,000 downloads), you should update it right away. During a routine audit for our Website Firewall (WAF), we found a dangerous vulnerability that could be used by a malicious...

  8. Drupal Warns - Every Drupal 7 Website Compromised Unless Patched

    Research Sucuri, 29 Oct 2014

    The Drupal team released an update to a critical SQL Injection vulnerability a few weeks ago and urged all their users to update or patch their sites immediately. If your site has been compromised you can use our free guide to fixing Dru...

  9. Threat Introduced via Browser Extensions

    Research Sucuri, 29 Oct 2014

    We love investigating unusual hacks. There are so many ways to compromise a website, but often it’s the same thing. When we see malicious code on web pages, our usual suspects are: Vulnerabilities in website software Trojanized software ...

  10. ASP Backdoors? Sure! It’s not just about PHP

    Research Sucuri, 27 Oct 2014

    I recently came to the realization that it might appear that we’re partial to PHP and WordPress. This realization has brought about an overwhelming need to correct that perception. While they do make up an interesting percentage, there a...

  11. Google Blacklists Bit.ly

    Research Sucuri, 25 Oct 2014

    If you ever shortened a URL using bit.ly or if you use it anywhere, be aware that Google recently blacklisted all bit.ly pages through its Safe Browsing program. It means that anyone using Chrome, Firefox or Safari will get a nasty The s...

  12. Popular Brazilian Site “Porta dos Fundos” Hacked

    Research Sucuri, 24 Oct 2014

    A very well known Brazilian comedy site, “Porta dos Fundos,” was recently hacked and is pushing malware (drive-by-download) via a malicious Flash executable, as you can see from our Sitecheck results: If you do not want the joke to be on...

  13. Manipulating WordPress Plugin Functions to Inject Malware

    Research Sucuri, 23 Oct 2014

    Most authors of website malware usually rely on the same tricks, making it easy for malware researchers to spot obfuscated code, random files that don’t belong, and malicious lines injected at the top of a file. However, it can become di...

  14. Chinese Doorway Spam - P2

    Research Sucuri, 21 Oct 2014

    We are seeing an increasing number of hacked sited with Chinese doorways promoting various fake merchandises (from Louis Vuitton handbags to NFL jerseys and Canada goose jackets). Those doorways target both Western web searches and the C...

  15. Drupal SQL Injection Attempts in the Wild

    Research Sucuri, 17 Oct 2014

    Update (2014/10/29): The Drupal team just released a Public Service Announcement, confirming what we are seeing (mass compromise of Drupal sites). We’ve released a new post with recovery information and a guide to cleaning Drupal hacks i...

  16. WordPress Websites Continue to Get Hacked via MailPoet Plugin Vulnerability

    Research Sucuri, 9 Oct 2014

    The popular Mailpoet(wysija-newsletters) WordPress plugin had a serious file upload vulnerability a few months back, allowing an attacker to upload files to vulnerable sites. This issue was disclosed months ago and the MailPoet team patc...

  17. Phishing with Help from Compromised WordPress Sites

    Research Sucuri, 6 Oct 2014

    We get thousands of spam and phishing emails daily. We use good spam filters (along with Gmail) and that greatly reduces the noise in our inbox. Today though, one slipped through the crack and showed up in my personal inbox: As I went to...

  18. Website Security: A Case of SEO Poisoning

    Research Sucuri, 2 Oct 2014

    There are so many ways your website can be co-opted by hackers for many different reasons, targeting the value created via your SEO is highly attractive. It provides an attacker the opportunity to cheat the system by quickly benefiting f...

  19. Website Malware - Curious .htaccess Conditional Redirect Case

    Research Sucuri, 23 Sep 2014

    I really enjoy when I see different types of conditional redirects on compromised sites. They are really hard to detect and always lead to interesting investigations. Take a look at this last one we identified: The curious aspect about i...

  20. Conditional Malicious iFrame Targeting WordPress Web Sites

    Research Sucuri, 19 Sep 2014

    We have an email address, labs@sucuri.net where we receive multiple questions a day about various forms of malware. One of the most common questions happen when our Free Security Scanner, SiteCheck, detects a spam injection or a hidden i...

  21. WordFence WordPress Security Plugin Pushes a Security Update

    Research Sucuri, 18 Sep 2014

    If you are one of the many users of the WordPress Security Plugin, WordFence, we highly encourage you to update. They recently pushed out a security update that could be affecting your install. It is important to note however that what i...

  22. The WordPress Security Plugin Ecosystem

    Research Sucuri, 16 Sep 2014

    As a child, did you ever play that game where you sit in a circle and one person is responsible for whispering something into one persons ear, and that message gets relayed around the circle? Wasn’t it always funny to see what the final ...

  23. Website Security - Compromised Website Used To Hack Home Routers

    Research Sucuri, 11 Sep 2014

    What if we told you that a compromised website has the ability to hack your home router? Yesterday we were notified that a popular newspaper in Brazil (politica.estadao.com.br) was hacked and loading several iframes. These iframes were t...

  24. Microsoft IIS Web Server - CMD Process Contributing to Website Reinfections

    Research Sucuri, 9 Sep 2014

    We often spend a lot of time talking about application level malware, but from time to time we do like to dabble in the ever so interesting web server infections as well. It is one of those things that comes with the job. Today, we’re go...

  25. Slider Revolution Plugin Critical Vulnerability Being Exploited

    Research Sucuri, 3 Sep 2014

    12.17.2014: See more information on the SoakSoak massive malware outbreak resulting from this vulnerability: RevSlider Vulnerability Leads To Massive WordPress SoakSoak Compromise by Daniel Cid If you need help cleaning a hacked WordPres...

  26. My WordPress Website Was Hacked

    Research Sucuri, 27 Aug 2014

    Before you freak out, allow me to clarify. It was one of several honeypots we have running. The honeypots are spread across the most commonly employed hosting companies. From Virtual Private Servers (VPS) to shared environments, to manag...

  27. Thoughts on WordPress Security and Vulnerabilities

    Research Sucuri, 15 Aug 2014

    As avid readers of this blog know, we’ve discovered or written about multiple vulnerabilities within the WordPress ecosystem over the last couple of weeks specifically relating to popular plugins. MailPoet and Custom Contact Forms drove ...

  28. Website Malware: Mobile Redirect to BaDoink Porn App Evolving

    Research Sucuri, 12 Aug 2014

    Recently, we wrote about a malware redirect causing compromised sites to redirect their visitors to pornographic content (specifically, the BaDoink app). You can read more about what we found by going to our previous blog post. As descri...

  29. Critical Vulnerability Disclosed on WordPress Custom Contact Forms Plugin

    Research Sucuri, 7 Aug 2014

    If you’re a using the Custom Contact Forms WordPress plugin, you need to update it right away. During a routine audit for our WAF, we found a critical vulnerability that allows an attacker to download and modify your database remotely (n...

  30. WordPress and Drupal Core Denial Of Service Vulnerability - Moderately Critical

    Research Sucuri, 6 Aug 2014

    Both WordPress and Drupal are affected by a DoS (denial of service) vulnerability on the PHP XML parser used by their XMLRPC implementations. The issue lies in the XML entity expansion parser that can cause CPU and memory exhaustion and ...

  31. Website Security Analysis: A “Simple” Piece of Malware

    Research Sucuri, 6 Aug 2014

    For regular readers of this blog, there is one constant that pops up over and over: Malware gets more complex. When malware researchers, like myself, unlock new obfuscated code, it’s a signal to the black hats that they need to up their ...

  32. Yoast and Sucuri Partner to Create a Safer Web

    Research Sucuri, 4 Aug 2014

    We’re very excited to finally talk about a partnership that’s been in the works for a few months and in light of the serious nature of the Security in the WordPress ecosystem it only makes sense. It also comes at a time where we, as an o...

  33. Backups - The Forgotten Website Security Pillar

    Research Sucuri, 31 Jul 2014

    I travel a lot (might actually be an understatement these days), but the travel always revolves around a couple of common threads - website security education and awareness. In these travels, regardless of whether I’m speaking with a Wor...

  34. New Brute Force Attacks Exploiting XMLRPC in WordPress

    Research Sucuri, 25 Jul 2014

    Brute force attacks against WordPress have always been very common. In fact, Brute Force attacks against any CMS these days is a common occurrence, what is always interesting however are the tools employed to make it happen. You create a...

  35. MailPoet Vulnerability Exploited in the Wild - Breaking Thousands of WordPress Sites

    Research Sucuri, 23 Jul 2014

    A few weeks ago we found and disclosed a serious vulnerability on the MailPoet WordPress Plugin. We urged everyone to upgrade their sites immediately due to the severity of the issue. The vulnerability allowed an attacker to inject anyth...

  36. Massive Malware Infection Breaking WordPress Sites

    Research Sucuri, 22 Jul 2014

    Update: We identified the root cause: MailPoet Vulnerability Exploited in the Wild - Breaking Thousands of WordPress Sites. The last few days has brought about a massive influx of broken WordPress websites. What makes it so unique is tha...

  37. Disclosure: Insecure Nonce Generation in WPtouch

    Research Sucuri, 14 Jul 2014

    If you use the popular WPtouch plugin (5M+ downloads) on your WordPress website, you should update it immediately. During a routine audit for our WAF, we discovered a very dangerous vulnerability that could potentially allow a user with ...

  38. Website Malware - Mobile Redirect to BaDoink Porn App

    Research Sucuri, 9 Jul 2014

    A few weeks ago we reported that we were seeing a huge increase in the number of websites compromised with a hidden redirection to pornographic content. It was a very tricky injection, with the redirection happening only once per day per...

  39. Ask Sucuri: Who is Logging into My WordPress Site?

    Research Sucuri, 3 Jul 2014

    Today, we’re going to revisit our Q&A series. If you have any questions about malware, blacklisting, or security in general, send them to us at: info@sucuri.net. For all the “Ask Sucuri” answers, go here. Question: How Do I Know Who is L...

  40. Remote File Upload Vulnerability in WordPress MailPoet Plugin (wysija-newsletters)

    Research Sucuri, 1 Jul 2014

    Marc-Alexandre Montpas, from our research team, found a serious security vulnerability in the MailPoet WordPress plugin. This bug allows an attacker to upload any file remotely to the vulnerable website (i.e., no authentication is requir...

  41. Spam Hack Targets WordPress Core Install Directories

    Research Sucuri, 24 Jun 2014

    Do you run your website on WordPress? Have you checked the integrity of your core install lately for SPAM like “Google Pharmacy” stores or other fake stores? We have been tracking and analyzing a growing trend in SEO spam, or Search Engi...

  42. Disclosure: Remote Code Execution Vuln in Disqus

    Research Sucuri, 21 Jun 2014

    We recently found a security vulnerability in the Disqus Comment System plugin for WordPress. It could, under very specific conditions, allow an attacker to perform arbitrary remote code execution (RCE). In other words, an attacker can d...

  43. Case Study: Complexities of “Simple” Malware

    Research Sucuri, 19 Jun 2014

    You know when you pull a string on a sweater and it just keeps going and going? You wonder when or if it will ever stop? From time to time, that’s how malware can feel. Even if you’re not a website security expert, it’s important to unde...

  44. Is My Website Hacked? If You Have to Ask, Then, “Yes.”

    Research Sucuri, 17 Jun 2014

    The problem with phishing, and therefore the reason so many people have trouble with it, is that the code is fairly benign and can be very difficult to spot. This is because it usually looks almost exactly like legitimate code. Oftentime...

  45. WordPress Plugin Alert - LoginWall Imposter Exposed

    Research Sucuri, 11 Jun 2014

    When you work with malware for a while, you start to become very good at pattern recognition. A couple sites in every hundred cleaned might be infected in a similar way, so remembering earlier problems helps to quickly solve the problem ...

  46. Take Back Your Internet - Demand a Safer Web

    Research Sucuri, 5 Jun 2014

    Over the last couple of weeks, we’ve written about malicious redirects pushing users to porn sites, ever more complicated phishing scams being carried out by multiple compromised websites on a single server and about adsense blackmail. W...

  47. Was the FIFA Website Hacked?

    Research Sucuri, 4 Jun 2014

    As many know, our company has deep Brazilian roots, as such we have no choice but to enamored with the upcoming World Cup. Yes, the World Cup is coming, soccer news is everywhere and like most things, websites are being used to dissemina...

  48. Vulnerability found in the All in One SEO Pack WordPress Plugin

    Research Sucuri, 31 May 2014

    The team behind the All in One SEO Pack just released a new version of their popular WordPress plugin. It is a security release patching two privilege escalation vulnerabilities we discovered earlier this week that may affect any web sit...

  49. Analyzing a Malicious iFrame - Following the Eval Trail

    Research Sucuri, 27 May 2014

    Over the last week, we’ve been working with some interesting malware injections. Developers and malware prevention professionals usually think of hidden iframes that deliver spam-seo or other malware as “easy to spot”. Take this injectio...

  50. Chinese Doorway Spam

    Research Sucuri, 27 May 2014

    We are seeing an increasing number of hacked sited with Chinese doorways promoting various fake merchandises (from Louis Vuitton handbags to NFL jerseys and Canada goose jackets). Those doorways target both Western web searches and the C...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support