Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 1 min ago.

  1. Website Malware Removal - WordPress Tips & Tricks

    Research Sucuri, 20 Jul 2012

    We released a new guide in 2016 that provides better instructions on how to clean a hacked WordPress site using the free WordPress security plugin. Guide on How to Clean a Hacked WordPress Site We often write posts that give you advice a...

  2. New Web Malware Attacks Using .Ru/In.CGI?16

    Research Sucuri, 19 Jul 2012

    What does an orange roller, a purple beetle, an orange moth, a green pillar, and a green cricket have in common? Not much, but they are all being used as malware domains to distribute .Ru/In.CGI?16 which is affecting thousands of web sit...

  3. Website Malware Removal - Counter.php

    Research Sucuri, 19 Jul 2012

    There are many variations to the Counter.php malware floating around the interwebs. This is a malicious redirect that sends your readers to a known bad site, that site houses a payload that responds based on the incoming user-agent. Mali...

  4. vBulletin Websites Using VBSEO Being Infected with Malware

    Research Sucuri, 16 Jul 2012

    We are seeing a large number of vBulletin/vBSEO websites getting compromised lately and we keep getting requests for info as to what’s going on. This is the type of malware being added to the hacked sites: eval ( function (p,a,c,k,e,d){e...

  5. Website Malware Removal - Blackhole Exploit

    Research Sucuri, 14 Jul 2012

    Here is a quick little write up on how to to deal with one, of many variations, of the Blackhole Exploit. The Infection If you scan your site using Sucuri SiteCheck and find yourself with a result that shows your site has been hacked// T...

  6. Fan of Twilight? Be Very Careful If You’re Looking Online For It

    Research Sucuri, 14 Jul 2012

    If you like the Twilight series, be careful if you plan to do any “research” on it, or if you plan to visit the site of the series author (Stephenie Meyer). Her site is currently hacked, blacklisted, and redirecting users to the Blackhol...

  7. ASK Sucuri: What should I do if my email is in the Yahoo Leak?

    Research Sucuri, 13 Jul 2012

    We love to get questions from you, our readers, in our Ask Sucuri series. If you have any questions about website malware, blacklisting, or security in general, send us an email to: info@sucuri.net or hit us on Twitter - @sucuri_security...

  8. Distributed Malware Network Outbreak Using Stats.php

    Research Sucuri, 8 Jul 2012

    We are seeing a large and distributed malware network comprised of thousands of infected websites that is growing very quickly. We call it “Stats.php” because all of the infected websites have the following iframe added to them: Stats.ph...

  9. Malware That Pretends To Be Google

    Research Sucuri, 6 Jul 2012

    Malware authors (AKA the criminals or the bad guys), use many advanced techniques to hide their activities. From encoding, to encrypting, to auto-generated random domains, conditional redirections and many other interesting methods. In t...

  10. Microsoft XML Core Service Zero Day Vulnerability Being Targeted

    Research Sucuri, 29 Jun 2012

    On June 12th we reported the release of a new Microsoft Security Advisory. It was of specific interest to us as it was exploitable via web-based malware and being classified as a Zero Day vulnerability. To that point, today, NakedSecurit...

  11. WordPress Update - 3.3.3 and 3.4.1 Patches Released!!

    Research Sucuri, 28 Jun 2012

    Well it was only a few weeks ago, but today, two new patches were released: 3.3.3 and 3.4.1. The good news is, as they are patches, the updates should be fairly straight forward and should not cause much, if any, issues. It is important ...

  12. Uploadify, Uploadify and Uploadify - The New TimThumb?

    Research Sucuri, 26 Jun 2012

    We are seeing a lot of noise again regarding the Uploadify script vulnerabilities affecting some WordPress themes/plugins. If you are not familiar, Uploadify allows anyone to upload anything they want to your site without any authenticat...

  13. Plesk Vulnerability Leading to Malware

    Research Sucuri, 26 Jun 2012

    Our friends over at Unmask Parasites posted two very good reports about a mix of Plesk vulnerabilities being used to mass-compromise websites, and redirecting them to the Blackhole Exploit Kit. The first issue is that old versions of Ple...

  14. How To: Lock Your Site by Enabling a Second Layer of Authentication

    Research Sucuri, 26 Jun 2012

    I put together a post this weekend about my personal experience installing a WordPress site on a clean Server. In the process of hardening the administration panel I found myself doing something that I don’t see discussed much - enabling...

  15. Sucuri Labs Weekly Review - June 22nd - 2012

    Research Sucuri, 24 Jun 2012

    Have you checked out Sucuri Labs? We have been adding a daily feed of the top web-based malware samples that we find every day, and the number of compromised sites as well. We separate the data into three main categories: Hidden iframes ...

  16. Understanding Conditional Malware - IP Centric Variation

    Research Sucuri, 22 Jun 2012

    In today’s web malware landscape you can’t help but take a minute to familiarize yourself with a concept known as conditional malware . As implied in the name, it’s malware that only works when specific rules are met. Those rules can ran...

  17. How To: Stop The Hacker By Hardening WordPress

    Research Sucuri, 20 Jun 2012

    Every day we service 100’s of clients and the question is always asked: How do you stop these hackers!!!” Unfortunately, it’s perhaps the hardest to explain and understand for most. That being said, this post will be one of a series that...

  18. How To: Lock Down WordPress Admin Panel With a Dynamic IP

    Research Sucuri, 16 Jun 2012

    There is often a lot of discussion around locking down access to WP-ADMIN and WP-Login.php, specially around restricting it by IP. The issues and retort that often comes up is, “but what if I have a dynamic IP?” Right away the response f...

  19. 3 Easy Steps to Make WordPress Updates Safer

    Research Sucuri, 14 Jun 2012

    With the release of WordPress 3.4 inching closer (could be minutes), we wanted to put together a quick post to help you towards a successful update. Here are a few areas to help you prepare for an easy update to the latest and greatest v...

  20. WordPress 3.4 Released - Update, Update, Update

    Research Sucuri, 13 Jun 2012

    It’s always very easy to say to update, but the harsh reality is that although the update process has been drastically streamlined over the past few years, there are always a few challenges. Its why we have put together a post on 3 easy ...

  21. Sucuri SiteCheck - Web Malware Distribution - May 2012

    Research Sucuri, 8 Jun 2012

    Last month ( May 2012), we were able to identify 94,866 compromised (hacked) websites using our free SiteCheck scanner. These were the top infections per distribution type (iframes and conditional redirections). A comparison to April can...

  22. Public Service Annoucement: LinkedIn Users Change Your Passwords

    Research Sucuri, 6 Jun 2012

    Rumors are quickly spreading on the web that approximately 6.5 million LinkedIn password hashes may have been leaked via a Russian hacker site. Regardless of the accuracy of the rumors many of you might want to take proactive steps and c...

  23. List of Domains Hosting Webshells for Timthumb Attacks

    Research Sucuri, 31 May 2012

    We have been tracking TimThumb related attacks for a while and they are still at full force (yes, some people are still using the outdated versions and getting compromised). Just for the month of May, we identified more than 400 domains ...

  24. WHMCS Website Hacked and Database Leaked

    Research Sucuri, 22 May 2012

    The WHMCS website and twitter accounts got compromised yesterday, and their full database (and files) were posted online. Yes, it means that if you have an account there, or if you use any of the WHMCS products, you have to change all yo...

  25. Websites Compromised with Fake AV Campaign (Windows Web Secure Kit)

    Research Sucuri, 15 May 2012

    “To help protect your computer, Windows Web Secure Kit have detected trojans and is ready to remove them” . We are seeing many WordPress sites compromised with a malware redirecting users to the “Windows Web Secure Kit” fake/rogue anti v...

  26. Official WordPress Plugin Directory - Forcing Plugin Updates

    Research Sucuri, 12 May 2012

    For some while we have wondered what happens when a plugin is removed from the official WordPress plugin directory for security reasons. Historically, we haven’t seen much of anything happen - no notification to users, no official blog p...

  27. Wpstats. org Spam and a Fake Advanced Search Plugin

    Research Sucuri, 9 May 2012

    If you are seeing hidden links in your WordPress site, it could be coming from wpstats.org. On some blackhat spam cases we are analysing, the following code was added to the theme header of the compromised site: if(function_exists(‘curl_...

  28. Sucuri WordPress Security Plugin Protects Against PHP-CGI Vulnerability

    Research Sucuri, 9 May 2012

    Today we released an update on the latest PHP CGI vulnerability and provided some additional information that users can use to help protect against it. Guidance includes updating your .htaccess file with the following: RewriteEngine on R...

  29. Sucuri SiteCheck - Web Malware Distribution - April 2012

    Research Sucuri, 1 May 2012

    When we see a compromised site distributing malware, it is often done via 4 methods: Iframe, Javascript, Spam or internal redirections. Those are not the only ways, and they can be encoded or hidden differently internally on the sites, b...

  30. New WooThemes Vulnerability Patched - Update Framework Now!

    Research Sucuri, 29 Apr 2012

    Yesterday a vulnerability on the WooThemes Framework was disclosed by Jason Gill on githumb:gist. The vulnerability allows a visitor to see and run the output of any shortcode configured on the WordPress site. At this time this does not ...

  31. Ransomware Malware on the Web?

    Research Sucuri, 28 Apr 2012

    As the week comes to a close I wanted to take a minute to talk about something we haven’t yet - Ransomware Malware. The idea came from a case this week where a client was defaced. Instead of engaging the host or malware professional she ...

  32. Sucuri Security WordPress Plugin Free To Clients: Getting Proactive with Web Malware

    Research Sucuri, 26 Apr 2012

    We are happy to announce that our premium WordPress plugin is now for free to all our existing and new clients. The plugin is a great compliment to our malware scanning and remediation services and provides a large array of features desi...

  33. Malware campaign against WordPress sites (recovery-hdd dot eu)

    Research Sucuri, 25 Apr 2012

    We have been tracking a new malware campaign that has been compromising thousands of WordPress sites over the last 3 days. They are not doing anything new, but using old vulnerabilities in plugins and themes, specially TimThumb, to add i...

  34. Ask Sucuri: What should I know when engaging a Web Malware Company?

    Research Sucuri, 24 Apr 2012

    We work in a business in which it is always chaos. In most situations the client is often distraught, vulnerable, and is plagued with this feeling of being out of control. It is the business of web malware cleanup. The last thing any web...

  35. Ask Sucuri: How to Stop The Hacker and ensure Your Site is Locked!

    Research Sucuri, 24 Apr 2012

    With the rise in web malware over the last 6 - 12 months, it’s important that we take some time to continue to educate and offer insight into ways that can help you stay ahead, in the hopes of stopping the hacker . Understanding The Hack...

  36. Nikjju SQL injection update (now hgbyju. com/r.php)

    Research Sucuri, 23 Apr 2012

    We posted a few days ago about a Mass SQL injection campaign that has been compromising thousands of sites. Our latest numbers show more than 200,000 pages got infected with the nikjju.com malware. However, since the last two days, the a...

  37. Web Malware Trends and the Mac Flashfake / Flashback Outbreak

    Research Sucuri, 20 Apr 2012

    This has been an interesting couple of weeks in the Anti-Virus world, specifically in the malware business for notebooks and desktops running the MAC OS. Securelist put out a very interesting post yesterday talking to the anatomy of the ...

  38. WordPress Security Release - Upgrade to 3.3.2 TODAY

    Research Sucuri, 20 Apr 2012

    It’s that time again, to upgrade all your WordPress installs. This morning the core team released WordPress 3.3.2 which includes security updates for three external libraries: Plupload (version 1.5.4), which WordPress uses for uploading ...

  39. GetMama - Conditional malware affecting thousands of sites

    Research Sucuri, 10 Apr 2012

    We have been tracking an interesting malware that is affecting thousands of compromised sites. We call it GetMama!! Why conditional? Because instead of just displaying the malicious code to all the visitors of the web site, it connects b...

  40. Sucuri SiteCheck - Web Malware Distribution - March 2012

    Research Sucuri, 5 Apr 2012

    Apologies for not posting stats for February. We were making some internal changes which delayed the process and skewed the data. Regardless, here are the latest stats for March. Note: This information is based on infections found using ...

  41. Varying Degrees of Malware Injections Decoded

    Research Sucuri, 30 Mar 2012

    It is no longer the day of human-readable injections, or even the use of basic encoding schemes like base64. Instead we’re seeing a rise in complex, and in some instances, elusive encoding schemes that carry with them a big punch. There ...

  42. Website Cross-contamination: Blackhat SEO Spam Malware

    Research Sucuri, 30 Mar 2012

    We recently posted about Website Cross-Contamination which we see quite a bit of in shared hosting environments. This post is a follow up with a nice sample of an SEO Spam infection that uses multiple sites in a shared environment to pus...

  43. WordPress Third Party Vulnerability - Deans FCKEditor with PWWANGS Code for WordPress(version 1.0.0)

    Research Sucuri, 30 Mar 2012

    You have heard me write in the past about understanding the true Vulnerability within WordPress. In that post I talk to the benefits of the platform and how those same benefits are also its weakness. This post is an example that brings t...

  44. Intelligent (Pharma) Spam Decoded

    Research Sucuri, 22 Mar 2012

    We are seeing a rise in the use of intelligent SPAM - a.k.a Pharma Hack - across a number of platforms. We recently found a nice injection that made us salivate, we figured you’d be just as interested It is of no surprise to us that atta...

  45. WordPress - Understanding its True Vulnerability

    Research Sucuri, 19 Mar 2012

    Everyday we manage thousands of clients running a wide range of applications, built across a number of different platforms. It should be of no surprise that a good number of them leverage the WordPress platform. This in itself can lead f...

  46. Brute force attacks against WordPress sites

    Research Sucuri, 15 Mar 2012

    We talk a lot about the importance of using strong passwords, but sometimes it it hard to see how important it really is, or what can happen if we do not use a strong one. Most people only realize this after they have been compromised fo...

  47. Conditional Redirect Malware Decoded - Eval base64_decode Example

    Research Sucuri, 15 Mar 2012

    I have this beautiful website and now there’s all this garbled code across all of my PHP files. What’s it do, and how did it get there? This is a quick post to show you some encoded crud that can attack your site, and do some pretty bad ...

  48. A Little Tale About Website Cross-Contamination

    Research Sucuri, 14 Mar 2012

    If you need help with a hacked site, we offer professional website malware removal services and will protect and monitor your website going forward. Mary has a site that she really cares about called mycoolsite.com. She has learned how t...

  49. Web Hosting Provider ServerPro Hacked, Defaced, & Blacklisted by Google

    Research Sucuri, 12 Mar 2012

    Even the pro’s are susceptible to attack. Web hosting provider ServerPro has been compromised and completely defaced. This has been ongoing for more than a few days with no resolution. ServerPro boasts to have over 200,000 clients over a...

  50. Latest Mass Compromise of WordPress sites - More Details

    Research Sucuri, 8 Mar 2012

    We are getting lots of questions about the latest mass compromise targeting WordPress sites (redirecting to fake AV) that has affected over 30,000 domains. The first question is how are these sites getting hacked? On all the cases we ana...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support