HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,885 reports kept since 2009. Updated automatically every 10 minutes. Last checked 1 min ago.
- Unauthenticated Broken Authentication Vulnerability in WordPress Jobmonster Theme
Research Patchstack, 18 Sep 2025
The TI WooCommerce Wishlist plugin, with over 100,000 active installs, is vulnerable to an unauthenticated file upload vulnerability (CVE-2025-47577).
- Unpatched Privilege Escalation in Service Finder Bookings Plugin
Research Patchstack, 3 Sep 2025
Critical WordPress security alert: Service Finder Bookings plugin allows unauthorized admin login. CVE-2025-23970 - no fix available yet! đźš«
- Vulnerability & Patch Roundup - August 2025
Research Sucuri, 1 Sep 2025
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- SQL Injection Vulnerability Patched in Paid Membership Subscriptions Plugin
Research Patchstack, 28 Aug 2025
The WP Job Portal plugin, with over 8,000 active installs, is vulnerable to unauthenticated SQL injection and arbitrary file read vulnerability.
- Creating an open alliance to secure the web
Research Patchstack, 27 Aug 2025
Over the years, we’ve witnessed many instances where critical security information fails to reach stakeholders as quickly as it should. Vulnerability databases help, but not all vulnerabilities are equal. Security teams from web hosts, p...
- What is Phishing?
Research Sucuri, 26 Aug 2025
Phishing is a serious threat to any industry. We have seen this topic appear in the news more each day. You might have already received a fraudulent email from what seemed to be your bank or even seen the hacking that took place during t...
- Locking Down the WordPress Login Page
Research Sucuri, 22 Aug 2025
Due to its flexibility, ease of use, and massive plugin ecosystem, WordPress is a favorite among bloggers, developers, and businesses alike. Given its popularity, attackers do not waste time guessing where sensitive assets live. By defau...
- Hosting security tested: 87.8% of vulnerability exploits bypassed hosting defenses
Research Patchstack, 21 Aug 2025
Are hosting companies’ standard network and server defenses enough to prevent exploits of WordPress vulnerabilities? The world of open-source is fraught with misconceptions, particularly when it comes to cybersecurity. It’s not uncommon ...
- SQL Injection Vulnerability Found in LifterLMS Plugin Affecting 10K+ Sites
Research Patchstack, 20 Aug 2025
This blog post is about LifterLMS theme vulnerabilities. If you’re a LifterLMS user, please update the plugin to version 8.0.7 or higher. About the LifterLMS Theme and Plugin The LifterLMS plugin, which has over 10,000 installations, is ...
- Malicious JavaScript Injects Fullscreen Iframe On a WordPress Website
Research Sucuri, 14 Aug 2025
Last month, we came across an ongoing JavaScript-based malware campaign affecting compromised websites. The malware injects a fullscreen iframe that silently loads content from a suspicious external domain. This type of malicious script ...
- Multiple Critical Vulnerabilities Patched in WP Job Portal Plugin
Research Patchstack, 12 Aug 2025
The WP Job Portal plugin, with over 8,000 active installs, is vulnerable to unauthenticated SQL injection and arbitrary file read vulnerability.
- SEO Spam Removal: Protect Search Rankings Before Blocklists Do
Research Sucuri, 8 Aug 2025
SEO spam used to be just annoying, but now it’s a huge moneymaker for organized crime. These groups are pushing fake meds, illegal gambling, and malware. The second they find a weak spot, they sneak in hidden links, crank out fake pages,...
- Is Drupal CMS a good alternative to WordPress? With Steve Persch of Pantheon
Research Patchstack, 6 Aug 2025
WordPress has had a turbulent year. Developers and agencies are asking hard questions about their platform choices. WordPress still powers about 40% of the web, but people are looking around, and Drupal is getting attention again. We spo...
- Critical Vulnerability Impacting Over 100K Sites Patched in Everest Forms Plugin
Research Patchstack, 6 Aug 2025
IMPORTANT UPDATE: On 3rd September, we got information on our Discord channel that this vulnerability is not practically exploitable due to the plugin initially checks if the current PHP version used on the server is below 7.1.3, and the...
- WordPress Vulnerability & Patch Roundup - July 2025
Research Sucuri, 31 Jul 2025
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- Security as Added Value: WP Umbrella Unlocks Additional Revenue in 3 Weeks
Research Patchstack, 30 Jul 2025
In a recent Patchstack webinar, Aurelio Volle, co-founder and CEO of WP Umbrella, shared what he’s learned building tools for WordPress professionals. Drawing on his agency background, Aurelio talked candidly about the pain points that l...
- Unauthenticated Arbitrary File Deletion Vulnerability in Litho Theme
Research Patchstack, 30 Jul 2025
This blog post is about an Unauthenticated Arbitrary File Deletion vulnerability in the Litho theme. If you’re a Litho theme user, please update the plugin to at least version 3.1. The vulnerability in the Litho theme was originally repo...
- Unauthorized Admin User Created via Disguised WordPress Plugin
Research Sucuri, 30 Jul 2025
Recently at Sucuri, we investigated a malware case reported by one of our clients. Their WordPress site was compromised, and the attacker had installed a fake plugin. Upon analysis revealed that it was a sophisticated backdoor plugin des...
- Account Takeover Vulnerability Affecting Over 400K Installations Patched in Post SMTP Plugin
Research Patchstack, 23 Jul 2025
This blog post is about a Subscriber+ account takeover (broken authentication) vulnerability in the Post SMTP plugin. If you’re a Post SMTP user, please update the plugin to at least version 3.3.0. The vulnerability in the Post SMTP plug...
- Uncovering a Stealthy WordPress Backdoor in mu-plugins
Research Sucuri, 22 Jul 2025
Recently, our team uncovered a particularly sneaky piece of malware tucked away in a place many WordPress users don’t even know exists: the mu-plugins folder. In fact, back in March, we saw a similar trend with hidden malware in this ver...
- WordPress Redirect Malware Hidden in Google Tag Manager Code
Research Sucuri, 18 Jul 2025
Last month, a customer contacted us after noticing their WordPress website was unexpectedly redirecting to a spam domain. The redirection occurred approximately 4-5 seconds after a user landed on the site. Upon closer inspection of the s...
- Case study: WP Umbrella Converts 4.5% of Sites to Patchstack in First 4 Weeks, Opening a New Revenue Stream
Research Patchstack, 16 Jul 2025
When WP Umbrella launched Patchstack as a security add-on, they didn’t expect results to come this fast. Within just four weeks, 4.5% of their managed sites had already upgraded, unlocking a new stream of recurring revenue, with zero fri...
- Account Takeover Vulnerability Patched in Password Policy Manager Plugin
Research Patchstack, 16 Jul 2025
The Password Policy Manager plugin, with over 5,000 active installs, is vulnerable to a subscriber+ account takeover vulnerability (CVE-2025-31019).
- Stealthy PHP Malware Uses ZIP Archive to Redirect WordPress Visitors
Research Sucuri, 11 Jul 2025
Last month, a customer contacted us, concerned about persistent and inexplicable redirects on their WordPress website. Our investigation quickly unearthed a sophisticated piece of malware deeply embedded within their site’s core files. T...
- Malware Found in Official GravityForms Plugin Indicating Supply Chain Breach
Research Patchstack, 11 Jul 2025
Update 7-12-2025 06:00 UTC: We have observed some activity in regard to one of the backdoors that involves a gf_api_token parameter. The IP address 193.160.101.6 tries to request, for every site, the following URLs with a spoofed user ag...
- Attackers Inject Code into WordPress Theme to Redirect Visitors
Research Sucuri, 9 Jul 2025
In a recent article we discussed some of the reasons sites are frequently attacked. That article covered browser redirects, and we’ll explore an example of such a case here. Website themes are a common attack vector for many reasons. The...
- Patchstack managed VDP report forwarding
Research Patchstack, 9 Jul 2025
As the leading threat intelligence provider in the WordPress ecosystem, Patchstack has more experience with validating reports and coordinating vulnerability disclosures than anyone else. Because of this, hundreds of WordPress plugin ven...
- WP Squared Integrates Patchstack Real-Time Protection to Safeguard Users
Research Patchstack, 7 Jul 2025
Security threats don’t wait for updates, and now, neither does WP Squared. We’re thrilled to announce that the WP Squared team has just rolled out Patchstack protection to deliver automated, proactive protection from plugin, theme, and c...
- Fake Spam Plugin Uses Victim’s Domain Name to Evade Detection
Research Sucuri, 2 Jul 2025
During our investigation of an SEO spam infection (spam content designed to manipulate search engine results), we discovered a nicely crafted plugin that named itself after the infected domain, helping it evade detection. While this tact...
- Vulnerability & Patch Roundup - June 2025
Research Sucuri, 1 Jul 2025
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- Stealthy WordPress Malware Drops Windows Trojan via PHP Backdoor
Research Sucuri, 27 Jun 2025
Last month, we encountered a particularly interesting and complex malware case that stood out from the usual infections we see in compromised WordPress websites. At first glance, the site looked clean, no visible signs of defacement, no ...
- Human-Centric Hosting in the Age of AI: Q&A with Zach Aufort of BigScoots
Research Patchstack, 27 Jun 2025
“We’re not just your hosting provider. We’re your support team, your troubleshooting partner, your safety net.” In a world where support tickets often trigger chatbot replies and plugin errors are met with a link to an FAQ, BigScoots is ...
- Case study: How BigScoots blocked 20k+ threats in 3 months with Patchstack
Research Patchstack, 26 Jun 2025
WordPress might be powering 40% of the internet, but every user has a different stack. And as a premium, fully-managed hosting provider for WordPress, BigScoots’s mission is to optimize and secure them all. Their secret sauce? Their part...
- The Case of Hidden Spam Pages
Research Sucuri, 25 Jun 2025
Spammy posts and pages being placed on WordPress websites is one of the most common infections that we come across. The reason being is that the attack is very low-level in terms of sophistication: All that is required of the attacker is...
- WP Umbrella Partners with Patchstack for Real-Time Vulnerability Protection
Research Patchstack, 24 Jun 2025
We’re excited to announce that WP Umbrella has deepened its security offering by integrating Patchstack protection into its Site Protect add-on. WP Umbrella users can now opt for Patchstack’s real-time protection right within their dashb...
- Malicious WordPress Plugin Creates Hidden Admin User Backdoor
Research Sucuri, 20 Jun 2025
I recently wrote about a case where a malicious plugin was used to steal admin credentials. Here we will examine yet another malicious plugin that creates a malicious admin user right in the website. Examining the malware While examining...
- Analysis of a Malicious WordPress Plugin: The Covert Redirector
Research Sucuri, 18 Jun 2025
A few weeks ago, we received a support request from a website owner who was experiencing unexpected redirects. Visitors landed on the website normally, but after about 4-5 seconds, the site redirected them to unrelated and suspicious web...
- Account Takeover Vulnerability in PayU CommercePro Plugin
Research Patchstack, 9 Jun 2025
The TI WooCommerce Wishlist plugin, with over 100,000 active installs, is vulnerable to an unauthenticated file upload vulnerability (CVE-2025-47577).
- NEW: Patchstack AI code review tool and Security Suite for plugin vendors
Research Patchstack, 5 Jun 2025
Today, we are super excited to launch the new version of the Patchstack mVDP platform, which now comes with an AI-based code review tool, team management features and a discussion board that helps plugin developers improve their code fas...
- Fake WordPress Caching Plugin Used to Steal Admin Credentials
Research Sucuri, 4 Jun 2025
A common trend we see is that bad actors will upload malicious plugins to WordPress sites. These plugins serve a wide variety of functions from injecting spam to redirecting sites to other malicious content. In this article we will exami...
- Vulnerability & Patch Roundup - May 2025
Research Sucuri, 31 May 2025
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- What Motivates Website Malware Attacks?
Research Sucuri, 28 May 2025
The depiction in the media of hackers tends to be that of balaclava-wearing villains who type furiously in a dark basement, motivated by nothing but evil intentions. However, while this may be true in some instances, by and large the det...
- Fake Java Update Popup Found in Malicious WordPress Plugin
Research Sucuri, 27 May 2025
We recently assisted a customer who reported a persistent and concerning “Java Update” pop-up appearing on their WordPress website. This type of deceptive notification is a common tactic used by attackers to compromise website visitors. ...
- Unpatched Critical Vulnerability in TI WooCommerce Wishlist Plugin
Research Patchstack, 27 May 2025
The TI WooCommerce Wishlist plugin, with over 100,000 active installs, is vulnerable to an unauthenticated file upload vulnerability (CVE-2025-47577).
- Fake Google Meet Page Tricks Users into Running PowerShell Malware
Research Sucuri, 23 May 2025
Last month, a customer reached out to us after noticing suspicious URLs on their WordPress site. Visitors reported being prompted to perform unusual actions. We began our investigation, scanning the site for common malware indicators and...
- WordPress Hosting Performance Promises and Security Realities: Q&A with Wes Tatters of Levamo
Research Patchstack, 23 May 2025
“Traditional hosting wasn’t built for the dynamic WordPress of today. It’s time we engineered solutions specifically for them.” WordPress has come a long way from blogs and brochure sites. Today, it powers e-learning platforms, communiti...
- Another Fake Cloudflare Verification Targets WordPress Sites
Research Sucuri, 21 May 2025
A new Cloudflare infection has once again been targeting WordPress sites. This new iteration of malware mimics a legitimate-looking Cloudflare verification page, which then tricks victims into following various commands and downloading m...
- Case study: Levamo moves fast - Patchstack makes sure it stays safe
Research Patchstack, 21 May 2025
The saying may be to “Move fast and break things,” but Levamo’s managed website hosting team knows that doesn’t have to be the case. As a provider offering hyperspeed performance, Levamo’s customers run complex WordPress sites with numer...
- Critical Privilege Escalation Vulnerability Patched in Eventin Plugin
Research Patchstack, 15 May 2025
The vulnerability in the Eventin plugin was originally reported by Patchstack Alliance community member Denver Jackson to the Patchstack Zero Day bug bounty program for WordPress. The Patchstack Zero Day program has awarded the researche...
- Case study: How Patchstack, Pagely & Crowd Favorite help secure one of the world’s largest media brands
Research Patchstack, 15 May 2025
If you work in a hosting company, you know the drill. A critical WordPress vulnerability gets disclosed, and within hours, your support team is flooded with tickets. Clients panic. Sites go down. Your team scrambles to clean up the mess....
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is ÂŁ249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed ÂŁ249, and we find how the attacker got in.