Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,885 reports kept since 2009. Updated automatically every 10 minutes. Last checked 1 min ago.

  1. Unauthenticated Broken Authentication Vulnerability in WordPress Jobmonster Theme

    Research Patchstack, 18 Sep 2025

    The TI WooCommerce Wishlist plugin, with over 100,000 active installs, is vulnerable to an unauthenticated file upload vulnerability (CVE-2025-47577).

  2. Unpatched Privilege Escalation in Service Finder Bookings Plugin

    Research Patchstack, 3 Sep 2025

    Critical WordPress security alert: Service Finder Bookings plugin allows unauthorized admin login. CVE-2025-23970 - no fix available yet! đźš«

  3. Vulnerability & Patch Roundup - August 2025

    Research Sucuri, 1 Sep 2025

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  4. SQL Injection Vulnerability Patched in Paid Membership Subscriptions Plugin

    Research Patchstack, 28 Aug 2025

    The WP Job Portal plugin, with over 8,000 active installs, is vulnerable to unauthenticated SQL injection and arbitrary file read vulnerability.

  5. Creating an open alliance to secure the web

    Research Patchstack, 27 Aug 2025

    Over the years, we’ve witnessed many instances where critical security information fails to reach stakeholders as quickly as it should. Vulnerability databases help, but not all vulnerabilities are equal. Security teams from web hosts, p...

  6. What is Phishing?

    Research Sucuri, 26 Aug 2025

    Phishing is a serious threat to any industry. We have seen this topic appear in the news more each day. You might have already received a fraudulent email from what seemed to be your bank or even seen the hacking that took place during t...

  7. Locking Down the WordPress Login Page

    Research Sucuri, 22 Aug 2025

    Due to its flexibility, ease of use, and massive plugin ecosystem, WordPress is a favorite among bloggers, developers, and businesses alike. Given its popularity, attackers do not waste time guessing where sensitive assets live. By defau...

  8. Hosting security tested: 87.8% of vulnerability exploits bypassed hosting defenses

    Research Patchstack, 21 Aug 2025

    Are hosting companies’ standard network and server defenses enough to prevent exploits of WordPress vulnerabilities? The world of open-source is fraught with misconceptions, particularly when it comes to cybersecurity. It’s not uncommon ...

  9. SQL Injection Vulnerability Found in LifterLMS Plugin Affecting 10K+ Sites

    Research Patchstack, 20 Aug 2025

    This blog post is about LifterLMS theme vulnerabilities. If you’re a LifterLMS user, please update the plugin to version 8.0.7 or higher. About the LifterLMS Theme and Plugin The LifterLMS plugin, which has over 10,000 installations, is ...

  10. Malicious JavaScript Injects Fullscreen Iframe On a WordPress Website

    Research Sucuri, 14 Aug 2025

    Last month, we came across an ongoing JavaScript-based malware campaign affecting compromised websites. The malware injects a fullscreen iframe that silently loads content from a suspicious external domain. This type of malicious script ...

  11. Multiple Critical Vulnerabilities Patched in WP Job Portal Plugin

    Research Patchstack, 12 Aug 2025

    The WP Job Portal plugin, with over 8,000 active installs, is vulnerable to unauthenticated SQL injection and arbitrary file read vulnerability.

  12. SEO Spam Removal: Protect Search Rankings Before Blocklists Do

    Research Sucuri, 8 Aug 2025

    SEO spam used to be just annoying, but now it’s a huge moneymaker for organized crime. These groups are pushing fake meds, illegal gambling, and malware. The second they find a weak spot, they sneak in hidden links, crank out fake pages,...

  13. Is Drupal CMS a good alternative to WordPress? With Steve Persch of Pantheon

    Research Patchstack, 6 Aug 2025

    WordPress has had a turbulent year. Developers and agencies are asking hard questions about their platform choices. WordPress still powers about 40% of the web, but people are looking around, and Drupal is getting attention again. We spo...

  14. Critical Vulnerability Impacting Over 100K Sites Patched in Everest Forms Plugin

    Research Patchstack, 6 Aug 2025

    IMPORTANT UPDATE: On 3rd September, we got information on our Discord channel that this vulnerability is not practically exploitable due to the plugin initially checks if the current PHP version used on the server is below 7.1.3, and the...

  15. WordPress Vulnerability & Patch Roundup - July 2025

    Research Sucuri, 31 Jul 2025

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  16. Security as Added Value: WP Umbrella Unlocks Additional Revenue in 3 Weeks

    Research Patchstack, 30 Jul 2025

    In a recent Patchstack webinar, Aurelio Volle, co-founder and CEO of WP Umbrella, shared what he’s learned building tools for WordPress professionals. Drawing on his agency background, Aurelio talked candidly about the pain points that l...

  17. Unauthenticated Arbitrary File Deletion Vulnerability in Litho Theme

    Research Patchstack, 30 Jul 2025

    This blog post is about an Unauthenticated Arbitrary File Deletion vulnerability in the Litho theme. If you’re a Litho theme user, please update the plugin to at least version 3.1. The vulnerability in the Litho theme was originally repo...

  18. Unauthorized Admin User Created via Disguised WordPress Plugin

    Research Sucuri, 30 Jul 2025

    Recently at Sucuri, we investigated a malware case reported by one of our clients. Their WordPress site was compromised, and the attacker had installed a fake plugin. Upon analysis revealed that it was a sophisticated backdoor plugin des...

  19. Account Takeover Vulnerability Affecting Over 400K Installations Patched in Post SMTP Plugin

    Research Patchstack, 23 Jul 2025

    This blog post is about a Subscriber+ account takeover (broken authentication) vulnerability in the Post SMTP plugin. If you’re a Post SMTP user, please update the plugin to at least version 3.3.0. The vulnerability in the Post SMTP plug...

  20. Uncovering a Stealthy WordPress Backdoor in mu-plugins

    Research Sucuri, 22 Jul 2025

    Recently, our team uncovered a particularly sneaky piece of malware tucked away in a place many WordPress users don’t even know exists: the mu-plugins folder. In fact, back in March, we saw a similar trend with hidden malware in this ver...

  21. WordPress Redirect Malware Hidden in Google Tag Manager Code

    Research Sucuri, 18 Jul 2025

    Last month, a customer contacted us after noticing their WordPress website was unexpectedly redirecting to a spam domain. The redirection occurred approximately 4-5 seconds after a user landed on the site. Upon closer inspection of the s...

  22. Case study: WP Umbrella Converts 4.5% of Sites to Patchstack in First 4 Weeks, Opening a New Revenue Stream

    Research Patchstack, 16 Jul 2025

    When WP Umbrella launched Patchstack as a security add-on, they didn’t expect results to come this fast. Within just four weeks, 4.5% of their managed sites had already upgraded, unlocking a new stream of recurring revenue, with zero fri...

  23. Account Takeover Vulnerability Patched in Password Policy Manager Plugin

    Research Patchstack, 16 Jul 2025

    The Password Policy Manager plugin, with over 5,000 active installs, is vulnerable to a subscriber+ account takeover vulnerability (CVE-2025-31019).

  24. Stealthy PHP Malware Uses ZIP Archive to Redirect WordPress Visitors

    Research Sucuri, 11 Jul 2025

    Last month, a customer contacted us, concerned about persistent and inexplicable redirects on their WordPress website. Our investigation quickly unearthed a sophisticated piece of malware deeply embedded within their site’s core files. T...

  25. Malware Found in Official GravityForms Plugin Indicating Supply Chain Breach

    Research Patchstack, 11 Jul 2025

    Update 7-12-2025 06:00 UTC: We have observed some activity in regard to one of the backdoors that involves a gf_api_token parameter. The IP address 193.160.101.6 tries to request, for every site, the following URLs with a spoofed user ag...

  26. Attackers Inject Code into WordPress Theme to Redirect Visitors

    Research Sucuri, 9 Jul 2025

    In a recent article we discussed some of the reasons sites are frequently attacked. That article covered browser redirects, and we’ll explore an example of such a case here. Website themes are a common attack vector for many reasons. The...

  27. Patchstack managed VDP report forwarding

    Research Patchstack, 9 Jul 2025

    As the leading threat intelligence provider in the WordPress ecosystem, Patchstack has more experience with validating reports and coordinating vulnerability disclosures than anyone else. Because of this, hundreds of WordPress plugin ven...

  28. WP Squared Integrates Patchstack Real-Time Protection to Safeguard Users

    Research Patchstack, 7 Jul 2025

    Security threats don’t wait for updates, and now, neither does WP Squared. We’re thrilled to announce that the WP Squared team has just rolled out Patchstack protection to deliver automated, proactive protection from plugin, theme, and c...

  29. Fake Spam Plugin Uses Victim’s Domain Name to Evade Detection

    Research Sucuri, 2 Jul 2025

    During our investigation of an SEO spam infection (spam content designed to manipulate search engine results), we discovered a nicely crafted plugin that named itself after the infected domain, helping it evade detection. While this tact...

  30. Vulnerability & Patch Roundup - June 2025

    Research Sucuri, 1 Jul 2025

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  31. Stealthy WordPress Malware Drops Windows Trojan via PHP Backdoor

    Research Sucuri, 27 Jun 2025

    Last month, we encountered a particularly interesting and complex malware case that stood out from the usual infections we see in compromised WordPress websites. At first glance, the site looked clean, no visible signs of defacement, no ...

  32. Human-Centric Hosting in the Age of AI: Q&A with Zach Aufort of BigScoots

    Research Patchstack, 27 Jun 2025

    “We’re not just your hosting provider. We’re your support team, your troubleshooting partner, your safety net.” In a world where support tickets often trigger chatbot replies and plugin errors are met with a link to an FAQ, BigScoots is ...

  33. Case study: How BigScoots blocked 20k+ threats in 3 months with Patchstack

    Research Patchstack, 26 Jun 2025

    WordPress might be powering 40% of the internet, but every user has a different stack. And as a premium, fully-managed hosting provider for WordPress, BigScoots’s mission is to optimize and secure them all. Their secret sauce? Their part...

  34. The Case of Hidden Spam Pages

    Research Sucuri, 25 Jun 2025

    Spammy posts and pages being placed on WordPress websites is one of the most common infections that we come across. The reason being is that the attack is very low-level in terms of sophistication: All that is required of the attacker is...

  35. WP Umbrella Partners with Patchstack for Real-Time Vulnerability Protection

    Research Patchstack, 24 Jun 2025

    We’re excited to announce that WP Umbrella has deepened its security offering by integrating Patchstack protection into its Site Protect add-on. WP Umbrella users can now opt for Patchstack’s real-time protection right within their dashb...

  36. Malicious WordPress Plugin Creates Hidden Admin User Backdoor

    Research Sucuri, 20 Jun 2025

    I recently wrote about a case where a malicious plugin was used to steal admin credentials. Here we will examine yet another malicious plugin that creates a malicious admin user right in the website. Examining the malware While examining...

  37. Analysis of a Malicious WordPress Plugin: The Covert Redirector

    Research Sucuri, 18 Jun 2025

    A few weeks ago, we received a support request from a website owner who was experiencing unexpected redirects. Visitors landed on the website normally, but after about 4-5 seconds, the site redirected them to unrelated and suspicious web...

  38. Account Takeover Vulnerability in PayU CommercePro Plugin

    Research Patchstack, 9 Jun 2025

    The TI WooCommerce Wishlist plugin, with over 100,000 active installs, is vulnerable to an unauthenticated file upload vulnerability (CVE-2025-47577).

  39. NEW: Patchstack AI code review tool and Security Suite for plugin vendors

    Research Patchstack, 5 Jun 2025

    Today, we are super excited to launch the new version of the Patchstack mVDP platform, which now comes with an AI-based code review tool, team management features and a discussion board that helps plugin developers improve their code fas...

  40. Fake WordPress Caching Plugin Used to Steal Admin Credentials

    Research Sucuri, 4 Jun 2025

    A common trend we see is that bad actors will upload malicious plugins to WordPress sites. These plugins serve a wide variety of functions from injecting spam to redirecting sites to other malicious content. In this article we will exami...

  41. Vulnerability & Patch Roundup - May 2025

    Research Sucuri, 31 May 2025

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  42. What Motivates Website Malware Attacks?

    Research Sucuri, 28 May 2025

    The depiction in the media of hackers tends to be that of balaclava-wearing villains who type furiously in a dark basement, motivated by nothing but evil intentions. However, while this may be true in some instances, by and large the det...

  43. Fake Java Update Popup Found in Malicious WordPress Plugin

    Research Sucuri, 27 May 2025

    We recently assisted a customer who reported a persistent and concerning “Java Update” pop-up appearing on their WordPress website. This type of deceptive notification is a common tactic used by attackers to compromise website visitors. ...

  44. Unpatched Critical Vulnerability in TI WooCommerce Wishlist Plugin

    Research Patchstack, 27 May 2025

    The TI WooCommerce Wishlist plugin, with over 100,000 active installs, is vulnerable to an unauthenticated file upload vulnerability (CVE-2025-47577).

  45. Fake Google Meet Page Tricks Users into Running PowerShell Malware

    Research Sucuri, 23 May 2025

    Last month, a customer reached out to us after noticing suspicious URLs on their WordPress site. Visitors reported being prompted to perform unusual actions. We began our investigation, scanning the site for common malware indicators and...

  46. WordPress Hosting Performance Promises and Security Realities: Q&A with Wes Tatters of Levamo

    Research Patchstack, 23 May 2025

    “Traditional hosting wasn’t built for the dynamic WordPress of today. It’s time we engineered solutions specifically for them.” WordPress has come a long way from blogs and brochure sites. Today, it powers e-learning platforms, communiti...

  47. Another Fake Cloudflare Verification Targets WordPress Sites

    Research Sucuri, 21 May 2025

    A new Cloudflare infection has once again been targeting WordPress sites. This new iteration of malware mimics a legitimate-looking Cloudflare verification page, which then tricks victims into following various commands and downloading m...

  48. Case study: Levamo moves fast - Patchstack makes sure it stays safe

    Research Patchstack, 21 May 2025

    The saying may be to “Move fast and break things,” but Levamo’s managed website hosting team knows that doesn’t have to be the case. As a provider offering hyperspeed performance, Levamo’s customers run complex WordPress sites with numer...

  49. Critical Privilege Escalation Vulnerability Patched in Eventin Plugin

    Research Patchstack, 15 May 2025

    The vulnerability in the Eventin plugin was originally reported by Patchstack Alliance community member Denver Jackson to the Patchstack Zero Day bug bounty program for WordPress. The Patchstack Zero Day program has awarded the researche...

  50. Case study: How Patchstack, Pagely & Crowd Favorite help secure one of the world’s largest media brands

    Research Patchstack, 15 May 2025

    If you work in a hosting company, you know the drill. A critical WordPress vulnerability gets disclosed, and within hours, your support team is flooded with tickets. Clients panic. Sites go down. Your team scrambles to clean up the mess....

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is ÂŁ249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed ÂŁ249, and we find how the attacker got in.

Get website support