HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 8 min ago.
- RSS Reveals Malware Injections
Research Sucuri, 19 Nov 2014
There are multiple different ways to detect invisible malware on a website: You can scrutinize the HTML code of web pages. Use external scanners like SiteCheck or UnmaskParasites. Get alerts from anti-viruses or search engines (both in s...
- The Art of Website Malware Removal - The Basics
Research Sucuri, 14 Nov 2014
When talking about defense against malicious hacks, the attack vector is a common topic for Information Security (InfoSec) professionals. The primary concern is to understand the anatomy of the attack and prevent it from happening again....
- The Psychology Behind Why Websites Get Hacked
Research Sucuri, 12 Nov 2014
It’s an everyday conversation for security professionals that interact with new customers. The one where we have to explain that just because everything seems fine, doesn’t mean that the best security practices shouldn’t be followed, or ...
- The Dangers of Hosted Scripts - Hacked jQuery Timers
Research Sucuri, 10 Nov 2014
Google blacklisted a client’s website claiming that malicious content was being displayed from “forogozoropoto(dot)2waky (dot)com” . A scan didn’t reveal anything suspicious. The next step was to check all third-party scripts on the webs...
- Combat Black Hat SEO Infections with SEO Insights
Research Sucuri, 7 Nov 2014
Black hat SEO spam is the plague of the internet, and the big search engines take it seriously. One of the worst spam tactics on the internet is becoming more common every day - innocent websites hacked, and their best pages begin linkin...
- Malicious iFrame Injector Found in Adobe Flash File (.SWF)
Research Sucuri, 5 Nov 2014
Finding malware in Adobe Flash files (.swf) is nothing new, but it usually affects personal computers, not servers. Typically, a hidden iframe is used to drop a binary browser exploit with .SWF files, infecting the client machine. This t...
- Security Advisory - Medium Severity - WP eCommerce WordPress Plugin
Research Sucuri, 31 Oct 2014
If you’re using the popular WP eCommerce WordPress plugin (2,900,000 downloads), you should update it right away. During a routine audit for our Website Firewall (WAF), we found a dangerous vulnerability that could be used by a malicious...
- Drupal Warns - Every Drupal 7 Website Compromised Unless Patched
Research Sucuri, 29 Oct 2014
The Drupal team released an update to a critical SQL Injection vulnerability a few weeks ago and urged all their users to update or patch their sites immediately. If your site has been compromised you can use our free guide to fixing Dru...
- Threat Introduced via Browser Extensions
Research Sucuri, 29 Oct 2014
We love investigating unusual hacks. There are so many ways to compromise a website, but often it’s the same thing. When we see malicious code on web pages, our usual suspects are: Vulnerabilities in website software Trojanized software ...
- ASP Backdoors? Sure! It’s not just about PHP
Research Sucuri, 27 Oct 2014
I recently came to the realization that it might appear that we’re partial to PHP and WordPress. This realization has brought about an overwhelming need to correct that perception. While they do make up an interesting percentage, there a...
- Google Blacklists Bit.ly
Research Sucuri, 25 Oct 2014
If you ever shortened a URL using bit.ly or if you use it anywhere, be aware that Google recently blacklisted all bit.ly pages through its Safe Browsing program. It means that anyone using Chrome, Firefox or Safari will get a nasty The s...
- Popular Brazilian Site “Porta dos Fundos” Hacked
Research Sucuri, 24 Oct 2014
A very well known Brazilian comedy site, “Porta dos Fundos,” was recently hacked and is pushing malware (drive-by-download) via a malicious Flash executable, as you can see from our Sitecheck results: If you do not want the joke to be on...
- Manipulating WordPress Plugin Functions to Inject Malware
Research Sucuri, 23 Oct 2014
Most authors of website malware usually rely on the same tricks, making it easy for malware researchers to spot obfuscated code, random files that don’t belong, and malicious lines injected at the top of a file. However, it can become di...
- Chinese Doorway Spam - P2
Research Sucuri, 21 Oct 2014
We are seeing an increasing number of hacked sited with Chinese doorways promoting various fake merchandises (from Louis Vuitton handbags to NFL jerseys and Canada goose jackets). Those doorways target both Western web searches and the C...
- Drupal SQL Injection Attempts in the Wild
Research Sucuri, 17 Oct 2014
Update (2014/10/29): The Drupal team just released a Public Service Announcement, confirming what we are seeing (mass compromise of Drupal sites). We’ve released a new post with recovery information and a guide to cleaning Drupal hacks i...
- WordPress Websites Continue to Get Hacked via MailPoet Plugin Vulnerability
Research Sucuri, 9 Oct 2014
The popular Mailpoet(wysija-newsletters) WordPress plugin had a serious file upload vulnerability a few months back, allowing an attacker to upload files to vulnerable sites. This issue was disclosed months ago and the MailPoet team patc...
- Phishing with Help from Compromised WordPress Sites
Research Sucuri, 6 Oct 2014
We get thousands of spam and phishing emails daily. We use good spam filters (along with Gmail) and that greatly reduces the noise in our inbox. Today though, one slipped through the crack and showed up in my personal inbox: As I went to...
- Website Security: A Case of SEO Poisoning
Research Sucuri, 2 Oct 2014
There are so many ways your website can be co-opted by hackers for many different reasons, targeting the value created via your SEO is highly attractive. It provides an attacker the opportunity to cheat the system by quickly benefiting f...
- Website Malware - Curious .htaccess Conditional Redirect Case
Research Sucuri, 23 Sep 2014
I really enjoy when I see different types of conditional redirects on compromised sites. They are really hard to detect and always lead to interesting investigations. Take a look at this last one we identified: The curious aspect about i...
- Conditional Malicious iFrame Targeting WordPress Web Sites
Research Sucuri, 19 Sep 2014
We have an email address, labs@sucuri.net where we receive multiple questions a day about various forms of malware. One of the most common questions happen when our Free Security Scanner, SiteCheck, detects a spam injection or a hidden i...
- WordFence WordPress Security Plugin Pushes a Security Update
Research Sucuri, 18 Sep 2014
If you are one of the many users of the WordPress Security Plugin, WordFence, we highly encourage you to update. They recently pushed out a security update that could be affecting your install. It is important to note however that what i...
- The WordPress Security Plugin Ecosystem
Research Sucuri, 16 Sep 2014
As a child, did you ever play that game where you sit in a circle and one person is responsible for whispering something into one persons ear, and that message gets relayed around the circle? Wasn’t it always funny to see what the final ...
- Website Security - Compromised Website Used To Hack Home Routers
Research Sucuri, 11 Sep 2014
What if we told you that a compromised website has the ability to hack your home router? Yesterday we were notified that a popular newspaper in Brazil (politica.estadao.com.br) was hacked and loading several iframes. These iframes were t...
- Microsoft IIS Web Server - CMD Process Contributing to Website Reinfections
Research Sucuri, 9 Sep 2014
We often spend a lot of time talking about application level malware, but from time to time we do like to dabble in the ever so interesting web server infections as well. It is one of those things that comes with the job. Today, we’re go...
- Slider Revolution Plugin Critical Vulnerability Being Exploited
Research Sucuri, 3 Sep 2014
12.17.2014: See more information on the SoakSoak massive malware outbreak resulting from this vulnerability: RevSlider Vulnerability Leads To Massive WordPress SoakSoak Compromise by Daniel Cid If you need help cleaning a hacked WordPres...
- My WordPress Website Was Hacked
Research Sucuri, 27 Aug 2014
Before you freak out, allow me to clarify. It was one of several honeypots we have running. The honeypots are spread across the most commonly employed hosting companies. From Virtual Private Servers (VPS) to shared environments, to manag...
- Thoughts on WordPress Security and Vulnerabilities
Research Sucuri, 15 Aug 2014
As avid readers of this blog know, we’ve discovered or written about multiple vulnerabilities within the WordPress ecosystem over the last couple of weeks specifically relating to popular plugins. MailPoet and Custom Contact Forms drove ...
- Website Malware: Mobile Redirect to BaDoink Porn App Evolving
Research Sucuri, 12 Aug 2014
Recently, we wrote about a malware redirect causing compromised sites to redirect their visitors to pornographic content (specifically, the BaDoink app). You can read more about what we found by going to our previous blog post. As descri...
- Critical Vulnerability Disclosed on WordPress Custom Contact Forms Plugin
Research Sucuri, 7 Aug 2014
If you’re a using the Custom Contact Forms WordPress plugin, you need to update it right away. During a routine audit for our WAF, we found a critical vulnerability that allows an attacker to download and modify your database remotely (n...
- WordPress and Drupal Core Denial Of Service Vulnerability - Moderately Critical
Research Sucuri, 6 Aug 2014
Both WordPress and Drupal are affected by a DoS (denial of service) vulnerability on the PHP XML parser used by their XMLRPC implementations. The issue lies in the XML entity expansion parser that can cause CPU and memory exhaustion and ...
- Website Security Analysis: A “Simple” Piece of Malware
Research Sucuri, 6 Aug 2014
For regular readers of this blog, there is one constant that pops up over and over: Malware gets more complex. When malware researchers, like myself, unlock new obfuscated code, it’s a signal to the black hats that they need to up their ...
- Yoast and Sucuri Partner to Create a Safer Web
Research Sucuri, 4 Aug 2014
We’re very excited to finally talk about a partnership that’s been in the works for a few months and in light of the serious nature of the Security in the WordPress ecosystem it only makes sense. It also comes at a time where we, as an o...
- Backups - The Forgotten Website Security Pillar
Research Sucuri, 31 Jul 2014
I travel a lot (might actually be an understatement these days), but the travel always revolves around a couple of common threads - website security education and awareness. In these travels, regardless of whether I’m speaking with a Wor...
- New Brute Force Attacks Exploiting XMLRPC in WordPress
Research Sucuri, 25 Jul 2014
Brute force attacks against WordPress have always been very common. In fact, Brute Force attacks against any CMS these days is a common occurrence, what is always interesting however are the tools employed to make it happen. You create a...
- MailPoet Vulnerability Exploited in the Wild - Breaking Thousands of WordPress Sites
Research Sucuri, 23 Jul 2014
A few weeks ago we found and disclosed a serious vulnerability on the MailPoet WordPress Plugin. We urged everyone to upgrade their sites immediately due to the severity of the issue. The vulnerability allowed an attacker to inject anyth...
- Massive Malware Infection Breaking WordPress Sites
Research Sucuri, 22 Jul 2014
Update: We identified the root cause: MailPoet Vulnerability Exploited in the Wild - Breaking Thousands of WordPress Sites. The last few days has brought about a massive influx of broken WordPress websites. What makes it so unique is tha...
- Disclosure: Insecure Nonce Generation in WPtouch
Research Sucuri, 14 Jul 2014
If you use the popular WPtouch plugin (5M+ downloads) on your WordPress website, you should update it immediately. During a routine audit for our WAF, we discovered a very dangerous vulnerability that could potentially allow a user with ...
- Website Malware - Mobile Redirect to BaDoink Porn App
Research Sucuri, 9 Jul 2014
A few weeks ago we reported that we were seeing a huge increase in the number of websites compromised with a hidden redirection to pornographic content. It was a very tricky injection, with the redirection happening only once per day per...
- Ask Sucuri: Who is Logging into My WordPress Site?
Research Sucuri, 3 Jul 2014
Today, we’re going to revisit our Q&A series. If you have any questions about malware, blacklisting, or security in general, send them to us at: info@sucuri.net. For all the “Ask Sucuri” answers, go here. Question: How Do I Know Who is L...
- Remote File Upload Vulnerability in WordPress MailPoet Plugin (wysija-newsletters)
Research Sucuri, 1 Jul 2014
Marc-Alexandre Montpas, from our research team, found a serious security vulnerability in the MailPoet WordPress plugin. This bug allows an attacker to upload any file remotely to the vulnerable website (i.e., no authentication is requir...
- Spam Hack Targets WordPress Core Install Directories
Research Sucuri, 24 Jun 2014
Do you run your website on WordPress? Have you checked the integrity of your core install lately for SPAM like “Google Pharmacy” stores or other fake stores? We have been tracking and analyzing a growing trend in SEO spam, or Search Engi...
- Disclosure: Remote Code Execution Vuln in Disqus
Research Sucuri, 21 Jun 2014
We recently found a security vulnerability in the Disqus Comment System plugin for WordPress. It could, under very specific conditions, allow an attacker to perform arbitrary remote code execution (RCE). In other words, an attacker can d...
- Case Study: Complexities of “Simple” Malware
Research Sucuri, 19 Jun 2014
You know when you pull a string on a sweater and it just keeps going and going? You wonder when or if it will ever stop? From time to time, that’s how malware can feel. Even if you’re not a website security expert, it’s important to unde...
- Is My Website Hacked? If You Have to Ask, Then, “Yes.”
Research Sucuri, 17 Jun 2014
The problem with phishing, and therefore the reason so many people have trouble with it, is that the code is fairly benign and can be very difficult to spot. This is because it usually looks almost exactly like legitimate code. Oftentime...
- WordPress Plugin Alert - LoginWall Imposter Exposed
Research Sucuri, 11 Jun 2014
When you work with malware for a while, you start to become very good at pattern recognition. A couple sites in every hundred cleaned might be infected in a similar way, so remembering earlier problems helps to quickly solve the problem ...
- Take Back Your Internet - Demand a Safer Web
Research Sucuri, 5 Jun 2014
Over the last couple of weeks, we’ve written about malicious redirects pushing users to porn sites, ever more complicated phishing scams being carried out by multiple compromised websites on a single server and about adsense blackmail. W...
- Was the FIFA Website Hacked?
Research Sucuri, 4 Jun 2014
As many know, our company has deep Brazilian roots, as such we have no choice but to enamored with the upcoming World Cup. Yes, the World Cup is coming, soccer news is everywhere and like most things, websites are being used to dissemina...
- Vulnerability found in the All in One SEO Pack WordPress Plugin
Research Sucuri, 31 May 2014
The team behind the All in One SEO Pack just released a new version of their popular WordPress plugin. It is a security release patching two privilege escalation vulnerabilities we discovered earlier this week that may affect any web sit...
- Analyzing a Malicious iFrame - Following the Eval Trail
Research Sucuri, 27 May 2014
Over the last week, we’ve been working with some interesting malware injections. Developers and malware prevention professionals usually think of hidden iframes that deliver spam-seo or other malware as “easy to spot”. Take this injectio...
- Chinese Doorway Spam
Research Sucuri, 27 May 2014
We are seeing an increasing number of hacked sited with Chinese doorways promoting various fake merchandises (from Louis Vuitton handbags to NFL jerseys and Canada goose jackets). Those doorways target both Western web searches and the C...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.