HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 4 min ago.
- Dre Armeda Presenting on WordPress Security at WordCamp Phoenix 2013
Research Sucuri, 2 Feb 2013
Here is the video for the WordPress Security presentation at WordCamp Phoenix 2013: Here is the slide deck from the presentation: Leave us your comments below. Continue reading Dre Armeda Presenting on WordPress Security at WordCamp Phoe...
- WordPress Security: 5 Steps To Reduce Your Risk
Research Sucuri, 25 Jan 2013
Update 11/3/2017: Check out our latest WordPress Security Guide for best practices to keep your website protected and learn about vulnerabilities. Often you hear the question, “What plugins should I use for WordPress Security?”. It’s a v...
- WordPress 3.5.1 Released
Research Sucuri, 24 Jan 2013
The WordPress team just pushed out a new version of WordPress (3.5.1) that has some security bugs fixed. Straight from their release post, these are the security changes: A server-side request forgery vulnerability and remote port scanni...
- Server Compromises - Understanding Apache Module iFrame Injections and Secure Shell Backdoor
Research Sucuri, 23 Jan 2013
There are many ways to inject a malicious payload onto a website. The attacker can modify any of the web files (index.php for example), the .htaccess file or php.ini (if the site is using PHP). There are other ways, but those are the mos...
- WordPress SPAM Causing Headaches
Research Sucuri, 17 Jan 2013
Newly Released: On 11/3/2017 we published our guide on how to secure your WordPress site and it also talks about vulnerabilities and best practices. It seems that SPAM is all the rave these days, wonder why, could it be because it’s a mu...
- WordCamp Las Vegas 2012 - Tony Perez: WordPress Security - Dealing with Today’s Hacks
Research Sucuri, 17 Jan 2013
Here is a great presentation given by Tony Perez our COO in October of 2012 at WordCamp Las Vegas: Continue reading WordCamp Las Vegas 2012 - Tony Perez: WordPress Security - Dealing with Today’s Hacks at Sucuri Blog.
- W3 Total Cache Implementation Vulnerability
Research Sucuri, 25 Dec 2012
Just in time for Christmas, it was announced on the full disclosure list a security (configuration/implementation) bug on W3 Total cache (W3TC), one of the most popular WordPress plugins. The issue is connected to the way W3TC stores the...
- Website Malware - Drupal Injections Targeting Cookies
Research Sucuri, 19 Dec 2012
Many folks are unfamiliar with the Drupal CMS, it doesn’t enjoy the popularity that some others do like WordPress and Joomla, but its a powerful CMS none the less. What it does have in common with its counterparts is that its susceptible...
- Website Malware - Sharp Increase in SPAM Attacks - WordPress & Joomla
Research Sucuri, 14 Dec 2012
This past week we have seen a sharp increase in the use of old tactics designed to poison your search engine results - also known as Search Engine Poisoning (SEP) attacks. If you use our free scanner, SiteCheck, you’ll likely see somethi...
- Website Malware - Reality of Cross-Site Contaminations
Research Sucuri, 13 Dec 2012
Sometimes you can’t help but put yourself in the shoes of your clients and skeptics and wonder how many times they roll their eyes at the things you say. Cross-site contamination is one of those things. We first start writing about it in...
- WordPress 3.5 Released
Research Sucuri, 11 Dec 2012
Update like it’s hot! Today marks the release of WordPress 3.5 (Named Elvin after jazz drimmer Elvin Jones), a major release this year for the WordPress project. This release highlights some very significant changes to anything from the ...
- Web Malware - Working with Evil Backdoors - Part III
Research Sucuri, 11 Dec 2012
The most complicated part of our job, when cleaning compromised web sites, is ensuring we find all backdoors. If we miss one, the site can be reinfected. We have done a few posts about backdoors already, explaining how they work and in t...
- ChangeIP (dynamic DNS) malware
Research Sucuri, 10 Dec 2012
If you look at the top domains distributing malware for the last days (and months), whatdo you see in common? #numberofsitesinfected #type #malwaredomain 650 iframe http://cvrtyi.ddns.info/nighttrend.cgi?8 315 iframe http://byiegfs.ddns....
- Sucuri SiteCheck Malware Scanner Plugin for WordPress
Research Sucuri, 7 Dec 2012
If you’re a WordPress user, love our free SiteCheck scanner, or already use our free SiteCheck Malware Scanner Plugin for WordPress, we have an update for you. Last night we released version 1.2 of the plugin which cleans up various part...
- Sucuri Launches Rapid+ Monitoring
Research Sucuri, 4 Dec 2012
A common feature our clients have been asking us for a long time is the ability to monitor their sites more frequently. For some high profile sites, scans every 6 hours is not enough. Today we are happy to announce that we added the Sucu...
- JavaScript Redirect Using Multiple Outdated Websites
Research Sucuri, 3 Dec 2012
This is a doozy. This case was really interesting to remediate as it consisted of multiple outdated websites in a shared environment. We’re talking known vulnerable instances of WordPress and TimThumb here. There were more than 8 website...
- Website Malware - Joomla SEP Attack - Pharma Injection
Research Sucuri, 29 Nov 2012
This was a fun, yet painful case. In the past we have written a few different posts targeting search engine poisoning attacks (SEP) that like to use Pharmaceutical keywords and their associated links to poison your search engine results....
- Piwik.org webserver hacked and backdoor added to Piwik
Research Sucuri, 27 Nov 2012
If you are using Piwik and you have downloaded/updated it recently, please double check your install to verify that it does not contain a backdoor. From piwik.org: Important Security Announcement: Piwik.org webserver got compromised by a...
- Website Malware Removal - FTP Tips & Tricks
Research Sucuri, 25 Nov 2012
Update 9/9/16 : We released a new guide that provides better instructions on how to clean a hacked WordPress site using the Free WordPress security plugin. 2016 Guide on How to Clean a Hacked WordPress Site When you clean as many sites a...
- Website Malware - SPAM Injections - HideMe - KickeMe
Research Sucuri, 23 Nov 2012
Every now and then you have to give thanks that attackers have a sense of humor. For the past few weeks, maybe months, who keeps track of time anyway, we have been seeing this injection and it makes us giggle like school girls every time...
- More Fake jQuery sites - jqueryc.com
Research Sucuri, 22 Nov 2012
We keep seeing fake jQuery sites popping up and being used to distributemalware. One was jquerys.org, other was jquery-framework.com and the new oneis jqueryc.com (199.59.241.179). And this new one seems to be affecting many web sites in...
- Website Malware - SEP Attack - SPAM Link Farm
Research Sucuri, 21 Nov 2012
How appropriate that less than a few hours from my last post talking about Search Engine Poisoning (SEP) attacks I come across a case that aims to land the sites visitors on a spam link farm. This is not an earth shattering post; it’s ju...
- Website Malware - SEO Poisoning Spam
Research Sucuri, 20 Nov 2012
Lately, we’ve been seeing a lot of SEO poisoning cases and felt it necessary to spend a little more time explaining them. SEO (Search Engine Optimization) is all the rave these days. Anybody that owns a website and is trying to make an i...
- co.cc seems to be gone
Research Sucuri, 20 Nov 2012
It seems that the .co.cc (sub TLD) that used to be mass used byspammers and malware is now gone. Their registration page is offline: $ host co.cc Host co.cc not found: 3(NXDOMAIN) $ host www.co.cc Host www.co.cc not found: 3(NXDOMAIN) An...
- New Google Chrome Blacklist Warning for Macs
Research Sucuri, 7 Nov 2012
If you go to a site that is Blacklisted by Google, you will see a new (and prettier) malware warning now if you are using a Mac: The Website Ahead Contains Malware! Google Chrome Has Blocked access to site.com for now. Even if you have v...
- Joomla Pharma Hack - Web Malware Removal
Research Sucuri, 6 Nov 2012
Nov 2016 Update: If your Joomla website has been hacked, you can follow our new guide to remove malware from Joomla site and protect your site in the future. Read the Guide Now! In my last SEO poisoning post I wrote about some really nas...
- Iframes generator: http://wordpresstest2.info/1.txt
Research Sucuri, 25 Oct 2012
If your site is loading hidden iframes from *.ftp1.biz/pony, look for a curlor file_get_contents call to http://wordpresstest2.info/1.txt.When you visit this site, it generates random iframes: http://lsghmr.ftp1.biz/pony ( 206.212.240.20...
- Ask Sucuri: How Does SiteCheck Work?
Research Sucuri, 20 Oct 2012
Question: How does SiteCheck work? I just scanned a site that I think is compromised but the scanner is showing it as clean. Is my site really clean or did you make a mistake? Answer: SiteCheck is our free, remote website scanner that wo...
- WordPress Security Hangout - Grand Rapids WP Meetup
Research Sucuri, 19 Oct 2012
Every now and then, trying to summarize a conversation doesn’t do it any justice. Here is the discussion in its entirety between Dre Armeda, Mark Jaquith and I, Tony Perez, for the recent Grand Rapids WP Meetup. As you might imagine, it’...
- Is WordPress.com SPAM Campaign Due to Compromise?
Research Sucuri, 16 Oct 2012
*****Updated - 20121019***** Both Matt Mullenweg and Barry Abrahamson, System Wrangler with Automattic, have confirmed that there was not an environmental compromise and everything was isolated to individual user accounts. Per their inci...
- Dealing with WordPress Malware
Research Sucuri, 11 Oct 2012
A few months back I contributed to a post with Smashing Magazine on the top 4 WordPress Infections, it was released yesterday, and it couldn’t have been at a better time. If any one attended WordCamp Las Vegas you might even find some si...
- WordPress Themes: XSS Vulnerabilities and Secure Coding Practices
Research Sucuri, 5 Oct 2012
As many might imagine, my life revolves around Information Security. If you’re like me, you’re undoubtedly seeing all these new posts talking to insecurities in WordPress themes, specifically a plethora of Cross-Site Scripting (XSS) vuln...
- Sorryforthiscode - iFrame Injection
Research Sucuri, 28 Sep 2012
We were working on a compromised site today that had some hidden iFrames on it. The iFrames were redirecting visitors to what seemed like random domains. This is the iFrame we were seeing: Nothing new, but we decided to check how popular...
- Careful With Fake jQuery Website - jquery-framework. com
Research Sucuri, 17 Sep 2012
A few days ago we posted in our Labs notes about a Fake jQuery website that is distributing malware. The domain was properly chosen to confuse the end-users ( jquery-framework.com ), since it looks like a valid site. This is what we were...
- WooThemes Security Audit Process & Development Partner WebDevStudios
Research Sucuri, 11 Sep 2012
WooThemes recently released a post talking to an audit that was performed on their various plugins and framework by our team. While true, it is important to note their level of commitment to providing secure products was second to none, ...
- Sociable WordPress Plugin Security Warning
Research Sucuri, 7 Sep 2012
If you are using the Sociable WordPress Plugin (plugin with 1,777,161 downloads), be very careful when visiting the plugin’s page settings . We recommend that you disable it or remove it for now, at least until it gets fixed. A customer ...
- WordPress 3.4.2 Released - Maintenance and Security Update!
Research Sucuri, 6 Sep 2012
As many know, today the WordPress team released a new patch for WordPress 3.4.2, and have titled it a maintenance and security release. By now many have regurgitated the same post in a number of different blogs and forums pushing the wor...
- WordPress Security - Cutting Through The BS
Research Sucuri, 30 Aug 2012
Update 9/9/16 : We released a new guide that provides better instructions on how to clean a hacked WordPress site using the Free WordPress security plugin. Update 11/3/2017: Proud to share with all of you our newest WP Security Guide tha...
- WordPress Security Presentation (in Portuguese)
Research Sucuri, 27 Aug 2012
Bruno Borges (from our security team), did a great presentation at WordCamp Sao Paulo (Brazil) about WordPress security and how to keep a site secure. The video is in Portuguese (pt-br), and can be viewed here: Watch live streaming video...
- Rebots.php JavaScript Malware Being Actively Injected
Research Sucuri, 24 Aug 2012
Holy JavaScript malware, Batman! On August 11th we started seeing the Rebot JavaScript malware string injected on various websites. Since then, it has increased its appearances, and has variated the way it’s being included on the infecte...
- WordPress Pluggable.php Being Compromised
Research Sucuri, 15 Aug 2012
The last few days we have seen a large number of WordPress sites compromised with a hidden malware payload that lands inside wp-includes/pluggable.php. This is not a WordPress vulnerability, WordPress is simply being targeted as the host...
- Redirection Malware Very Good Leads to Fake AV
Research Sucuri, 8 Aug 2012
If you look at our Labs malware dump for the last few days, you will find something odd in the name of the top domains distributing malware: 712 redirections http://moi-verygoods.ru/simmetry?6 154 redirections http://moiverygoods.ru/simm...
- Secure Website Development - Importance of Developing Securely
Research Sucuri, 1 Aug 2012
We clean hundreds of sites every day and often their problems are associated with the same issues: outdated and sometimes unnecessary software, weak passwords and so on. But sometimes the issue is not as superficial, sometimes it goes a ...
- Blackmuscats Conditional Redirections to Fake AntiVirus
Research Sucuri, 31 Jul 2012
We are seeing many sites today compromised with the Blackmuscats conditional redirection. This malware causes anyone visiting the hacked site to be redirected to a Fake AV (AntiVirus). Why Blackmuscats? All the compromised sites have .ht...
- WordPress and Server Hardening - Taking Security to Another Level
Research Sucuri, 27 Jul 2012
Update 11/3/2017: Need to learn how to secure your WP site ? Check out our latest guide on vulnerabilities, best practices and protection. Update 9/14/16 : We released a new guide that provides better instructions on how to clean a hacke...
- Website Malware Removal - Website Redirection
Research Sucuri, 26 Jul 2012
This post was put together in collaboration with one of our Support Engineers, Bruno Borges. Be sure to take a minute and say thanks for the info, he loves twitter (when its up). It seems every day we’re combating malicious redirections....
- Backdoor Tool Kit - Today’s Scary Web Malware Reality
Research Sucuri, 25 Jul 2012
We often talk about the importance of keeping your server clean. You can see it in a number of our articles and presentations, this post will likely drive that point home. This past week we came across a nice little package that we felt ...
- Pharma Hack Backdoor Analyzed - PHP5.PHP
Research Sucuri, 23 Jul 2012
Some of you might remember my last Pharma hack post, Intelligent (Pharma) SPAM Decoded, today I will spend some time looking a different variant of the same infection type but focus on a payload that is not encoded or embedded within an ...
- Fake jQuery Website Serving Redirection Malware
Research Sucuri, 20 Jul 2012
This just in, hot off the press, careful with the jQuery libraries you’re using on your websites. We received word from @chris_olbekson via Twitter about some hacks being reported on the WordPress forums: The tweet links to a the fake jQ...
- Sneaky vBulletin Script Injections
Research Sucuri, 20 Jul 2012
In the past few days/weeks we have been seeing some nasty vBulletin infections that are proving difficult to find. In this post we’ll describe it and what we have done to remove it. We recently wrote about Conditional Malware, this is bu...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.