HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,887 reports kept since 2009. Updated automatically every 10 minutes. Last checked 10 min ago.
- Website Malware - Fixing Joomla SPAM Hacks - Conditional Payloads
Research Sucuri, 22 Feb 2013
Our Senior Malware Engineer, Fioravante Cavallari, is at it again. I think he has made it his personal mission in life to expel all Joomla hacks, he loves them that much - true story.. đ In all seriousness, he found another gem yesterda...
- NBC Website HACKED - Be Careful Surfing
Research Sucuri, 21 Feb 2013
Breaking, the NBC site is currently compromised and blacklisted by Google. Anyone that visits the site (which includes any sub page) will have malicious iframes loaded as well redirecting the user to exploit kits (Redkit): *Update: Not o...
- Sneaky Joomla Web Malware - JavaScript Infections
Research Sucuri, 19 Feb 2013
So the past week has been interesting, we have been having fun with a few JavaScript infections that really forced us to put on our thinking hats. Our Senior Malware Engineer, Fioravante Cavallari, actually found the payload and dissecte...
- WordPress Plugin: Easy Digital Downloads - Security Flaw Discovered and Patchedd
Research Sucuri, 16 Feb 2013
Last night we were contacted by Adam Pickering about a security flaw discovered in Easy Digital Downloads (EDD), a free WordPress eCommerce plugin that allows you to sell digital downloads. If you use EDD and havenât done so already, ple...
- Large Scale Compromises Leading to Traffic Distribution System
Research Sucuri, 15 Feb 2013
For the last few weeks weâve been tracking a large scale decentralized Traffic Distribution System (TDS). Itâs using hundreds of compromised sites as their first entry point. Anyone that visits the compromised sites from a search engine ...
- Large scale TDS redirections
Research Sucuri, 15 Feb 2013
Lots of compromised sites redirecting to TDS: http://1151.website.snafu.de/hkkj.html?h=1475928 http://adaptpro.co.uk/mwhi.html?h=1380448 http://aennekens.de/hozs.html?h=1180315 http://afamontserrat.org/zapn.html?h=877095 http://afhwarran...
- Various Shades of Malware - Abusing Your Resources
Research Sucuri, 14 Feb 2013
We often write about very clear cut cases of malware activity. The attacker is leveraging your traffic, redirecting it to other locations, or injecting things like iFrames in an attempt to perform some type of drive-by-download. These ar...
- Malware Redirection with a Delay
Research Sucuri, 13 Feb 2013
You visit a site and it looks good and clean. However, if you keep the page open, after maybe 20-30 seconds, you get redirected to a casino or pharma affiliate page. What is going on? We call these delayed redirections and they are becom...
- Dre Armeda Presenting on WordPress Security at WordCamp Phoenix 2013
Research Sucuri, 2 Feb 2013
Here is the video for the WordPress Security presentation at WordCamp Phoenix 2013: Here is the slide deck from the presentation: Leave us your comments below. Continue reading Dre Armeda Presenting on WordPress Security at WordCamp Phoe...
- WordPress Security: 5 Steps To Reduce Your Risk
Research Sucuri, 25 Jan 2013
Update 11/3/2017: Check out our latest WordPress Security Guide for best practices to keep your website protected and learn about vulnerabilities. Often you hear the question, âWhat plugins should I use for WordPress Security?â. Itâs a v...
- WordPress 3.5.1 Released
Research Sucuri, 24 Jan 2013
The WordPress team just pushed out a new version of WordPress (3.5.1) that has some security bugs fixed. Straight from their release post, these are the security changes: A server-side request forgery vulnerability and remote port scanni...
- Server Compromises - Understanding Apache Module iFrame Injections and Secure Shell Backdoor
Research Sucuri, 23 Jan 2013
There are many ways to inject a malicious payload onto a website. The attacker can modify any of the web files (index.php for example), the .htaccess file or php.ini (if the site is using PHP). There are other ways, but those are the mos...
- WordPress SPAM Causing Headaches
Research Sucuri, 17 Jan 2013
Newly Released: On 11/3/2017 we published our guide on how to secure your WordPress site and it also talks about vulnerabilities and best practices. It seems that SPAM is all the rave these days, wonder why, could it be because itâs a mu...
- WordCamp Las Vegas 2012 - Tony Perez: WordPress Security - Dealing with Todayâs Hacks
Research Sucuri, 17 Jan 2013
Here is a great presentation given by Tony Perez our COO in October of 2012 at WordCamp Las Vegas: Continue reading WordCamp Las Vegas 2012 - Tony Perez: WordPress Security - Dealing with Todayâs Hacks at Sucuri Blog.
- W3 Total Cache Implementation Vulnerability
Research Sucuri, 25 Dec 2012
Just in time for Christmas, it was announced on the full disclosure list a security (configuration/implementation) bug on W3 Total cache (W3TC), one of the most popular WordPress plugins. The issue is connected to the way W3TC stores the...
- Website Malware - Drupal Injections Targeting Cookies
Research Sucuri, 19 Dec 2012
Many folks are unfamiliar with the Drupal CMS, it doesnât enjoy the popularity that some others do like WordPress and Joomla, but its a powerful CMS none the less. What it does have in common with its counterparts is that its susceptible...
- Website Malware - Sharp Increase in SPAM Attacks - WordPress & Joomla
Research Sucuri, 14 Dec 2012
This past week we have seen a sharp increase in the use of old tactics designed to poison your search engine results - also known as Search Engine Poisoning (SEP) attacks. If you use our free scanner, SiteCheck, youâll likely see somethi...
- Website Malware - Reality of Cross-Site Contaminations
Research Sucuri, 13 Dec 2012
Sometimes you canât help but put yourself in the shoes of your clients and skeptics and wonder how many times they roll their eyes at the things you say. Cross-site contamination is one of those things. We first start writing about it in...
- WordPress 3.5 Released
Research Sucuri, 11 Dec 2012
Update like itâs hot! Today marks the release of WordPress 3.5 (Named Elvin after jazz drimmer Elvin Jones), a major release this year for the WordPress project. This release highlights some very significant changes to anything from the ...
- Web Malware - Working with Evil Backdoors - Part III
Research Sucuri, 11 Dec 2012
The most complicated part of our job, when cleaning compromised web sites, is ensuring we find all backdoors. If we miss one, the site can be reinfected. We have done a few posts about backdoors already, explaining how they work and in t...
- ChangeIP (dynamic DNS) malware
Research Sucuri, 10 Dec 2012
If you look at the top domains distributing malware for the last days (and months), whatdo you see in common? #numberofsitesinfected #type #malwaredomain 650 iframe http://cvrtyi.ddns.info/nighttrend.cgi?8 315 iframe http://byiegfs.ddns....
- Sucuri SiteCheck Malware Scanner Plugin for WordPress
Research Sucuri, 7 Dec 2012
If youâre a WordPress user, love our free SiteCheck scanner, or already use our free SiteCheck Malware Scanner Plugin for WordPress, we have an update for you. Last night we released version 1.2 of the plugin which cleans up various part...
- Sucuri Launches Rapid+ Monitoring
Research Sucuri, 4 Dec 2012
A common feature our clients have been asking us for a long time is the ability to monitor their sites more frequently. For some high profile sites, scans every 6 hours is not enough. Today we are happy to announce that we added the Sucu...
- JavaScript Redirect Using Multiple Outdated Websites
Research Sucuri, 3 Dec 2012
This is a doozy. This case was really interesting to remediate as it consisted of multiple outdated websites in a shared environment. Weâre talking known vulnerable instances of WordPress and TimThumb here. There were more than 8 website...
- Website Malware - Joomla SEP Attack - Pharma Injection
Research Sucuri, 29 Nov 2012
This was a fun, yet painful case. In the past we have written a few different posts targeting search engine poisoning attacks (SEP) that like to use Pharmaceutical keywords and their associated links to poison your search engine results....
- Piwik.org webserver hacked and backdoor added to Piwik
Research Sucuri, 27 Nov 2012
If you are using Piwik and you have downloaded/updated it recently, please double check your install to verify that it does not contain a backdoor. From piwik.org: Important Security Announcement: Piwik.org webserver got compromised by a...
- Website Malware Removal - FTP Tips & Tricks
Research Sucuri, 25 Nov 2012
Update 9/9/16 : We released a new guide that provides better instructions on how to clean a hacked WordPress site using the Free WordPress security plugin. 2016 Guide on How to Clean a Hacked WordPress Site When you clean as many sites a...
- Website Malware - SPAM Injections - HideMe - KickeMe
Research Sucuri, 23 Nov 2012
Every now and then you have to give thanks that attackers have a sense of humor. For the past few weeks, maybe months, who keeps track of time anyway, we have been seeing this injection and it makes us giggle like school girls every time...
- More Fake jQuery sites - jqueryc.com
Research Sucuri, 22 Nov 2012
We keep seeing fake jQuery sites popping up and being used to distributemalware. One was jquerys.org, other was jquery-framework.com and the new oneis jqueryc.com (199.59.241.179). And this new one seems to be affecting many web sites in...
- Website Malware - SEP Attack - SPAM Link Farm
Research Sucuri, 21 Nov 2012
How appropriate that less than a few hours from my last post talking about Search Engine Poisoning (SEP) attacks I come across a case that aims to land the sites visitors on a spam link farm. This is not an earth shattering post; itâs ju...
- Website Malware - SEO Poisoning Spam
Research Sucuri, 20 Nov 2012
Lately, weâve been seeing a lot of SEO poisoning cases and felt it necessary to spend a little more time explaining them. SEO (Search Engine Optimization) is all the rave these days. Anybody that owns a website and is trying to make an i...
- co.cc seems to be gone
Research Sucuri, 20 Nov 2012
It seems that the .co.cc (sub TLD) that used to be mass used byspammers and malware is now gone. Their registration page is offline: $ host co.cc Host co.cc not found: 3(NXDOMAIN) $ host www.co.cc Host www.co.cc not found: 3(NXDOMAIN) An...
- New Google Chrome Blacklist Warning for Macs
Research Sucuri, 7 Nov 2012
If you go to a site that is Blacklisted by Google, you will see a new (and prettier) malware warning now if you are using a Mac: The Website Ahead Contains Malware! Google Chrome Has Blocked access to site.com for now. Even if you have v...
- Joomla Pharma Hack - Web Malware Removal
Research Sucuri, 6 Nov 2012
Nov 2016 Update: If your Joomla website has been hacked, you can follow our new guide to remove malware from Joomla site and protect your site in the future. Read the Guide Now! In my last SEO poisoning post I wrote about some really nas...
- Iframes generator: http://wordpresstest2.info/1.txt
Research Sucuri, 25 Oct 2012
If your site is loading hidden iframes from *.ftp1.biz/pony, look for a curlor file_get_contents call to http://wordpresstest2.info/1.txt.When you visit this site, it generates random iframes: http://lsghmr.ftp1.biz/pony ( 206.212.240.20...
- Ask Sucuri: How Does SiteCheck Work?
Research Sucuri, 20 Oct 2012
Question: How does SiteCheck work? I just scanned a site that I think is compromised but the scanner is showing it as clean. Is my site really clean or did you make a mistake? Answer: SiteCheck is our free, remote website scanner that wo...
- WordPress Security Hangout - Grand Rapids WP Meetup
Research Sucuri, 19 Oct 2012
Every now and then, trying to summarize a conversation doesnât do it any justice. Here is the discussion in its entirety between Dre Armeda, Mark Jaquith and I, Tony Perez, for the recent Grand Rapids WP Meetup. As you might imagine, itâ...
- Is WordPress.com SPAM Campaign Due to Compromise?
Research Sucuri, 16 Oct 2012
*****Updated - 20121019***** Both Matt Mullenweg and Barry Abrahamson, System Wrangler with Automattic, have confirmed that there was not an environmental compromise and everything was isolated to individual user accounts. Per their inci...
- Dealing with WordPress Malware
Research Sucuri, 11 Oct 2012
A few months back I contributed to a post with Smashing Magazine on the top 4 WordPress Infections, it was released yesterday, and it couldnât have been at a better time. If any one attended WordCamp Las Vegas you might even find some si...
- WordPress Themes: XSS Vulnerabilities and Secure Coding Practices
Research Sucuri, 5 Oct 2012
As many might imagine, my life revolves around Information Security. If youâre like me, youâre undoubtedly seeing all these new posts talking to insecurities in WordPress themes, specifically a plethora of Cross-Site Scripting (XSS) vuln...
- Sorryforthiscode - iFrame Injection
Research Sucuri, 28 Sep 2012
We were working on a compromised site today that had some hidden iFrames on it. The iFrames were redirecting visitors to what seemed like random domains. This is the iFrame we were seeing: Nothing new, but we decided to check how popular...
- Careful With Fake jQuery Website - jquery-framework. com
Research Sucuri, 17 Sep 2012
A few days ago we posted in our Labs notes about a Fake jQuery website that is distributing malware. The domain was properly chosen to confuse the end-users ( jquery-framework.com ), since it looks like a valid site. This is what we were...
- WooThemes Security Audit Process & Development Partner WebDevStudios
Research Sucuri, 11 Sep 2012
WooThemes recently released a post talking to an audit that was performed on their various plugins and framework by our team. While true, it is important to note their level of commitment to providing secure products was second to none, ...
- Sociable WordPress Plugin Security Warning
Research Sucuri, 7 Sep 2012
If you are using the Sociable WordPress Plugin (plugin with 1,777,161 downloads), be very careful when visiting the pluginâs page settings . We recommend that you disable it or remove it for now, at least until it gets fixed. A customer ...
- WordPress 3.4.2 Released - Maintenance and Security Update!
Research Sucuri, 6 Sep 2012
As many know, today the WordPress team released a new patch for WordPress 3.4.2, and have titled it a maintenance and security release. By now many have regurgitated the same post in a number of different blogs and forums pushing the wor...
- WordPress Security - Cutting Through The BS
Research Sucuri, 30 Aug 2012
Update 9/9/16 : We released a new guide that provides better instructions on how to clean a hacked WordPress site using the Free WordPress security plugin. Update 11/3/2017: Proud to share with all of you our newest WP Security Guide tha...
- WordPress Security Presentation (in Portuguese)
Research Sucuri, 27 Aug 2012
Bruno Borges (from our security team), did a great presentation at WordCamp Sao Paulo (Brazil) about WordPress security and how to keep a site secure. The video is in Portuguese (pt-br), and can be viewed here: Watch live streaming video...
- Rebots.php JavaScript Malware Being Actively Injected
Research Sucuri, 24 Aug 2012
Holy JavaScript malware, Batman! On August 11th we started seeing the Rebot JavaScript malware string injected on various websites. Since then, it has increased its appearances, and has variated the way itâs being included on the infecte...
- WordPress Pluggable.php Being Compromised
Research Sucuri, 15 Aug 2012
The last few days we have seen a large number of WordPress sites compromised with a hidden malware payload that lands inside wp-includes/pluggable.php. This is not a WordPress vulnerability, WordPress is simply being targeted as the host...
- Redirection Malware Very Good Leads to Fake AV
Research Sucuri, 8 Aug 2012
If you look at our Labs malware dump for the last few days, you will find something odd in the name of the top domains distributing malware: 712 redirections http://moi-verygoods.ru/simmetry?6 154 redirections http://moiverygoods.ru/simm...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is ÂŁ249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed ÂŁ249, and we find how the attacker got in.