HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,879 reports kept since 2009. Updated automatically every 10 minutes. Last checked 3 min ago.
- Ask Sucuri: Talk More About Web-Based Malware
Research Sucuri, 2 Mar 2012
If you have any questions about malware, blacklisting, or security in general, send it to us: contact@sucuri.net and we will answer here. For all the “Ask Aucuri” answers, go here. Question: My site got hacked and it is distributing malw...
- Dangerous Backdoor - UTF8GAT.PHP
Research Sucuri, 1 Mar 2012
There is a very prominent backdoor being used extensively across a lot of the sites we are working on these days. This backdoor is giving the attacker[s] full control of your server. File to be on the look out for: utf8gat.php Once in yo...
- Malware Campaign from .rr.nu
Research Sucuri, 27 Feb 2012
No, they don’t quit, so get used to it! We are seeing quite a few websites being compromised with malware getting loaded from random domains in the .rr.nu TLD. This is what gets added to the footer of the hacked sites: Once loaded, it do...
- Vulnerability in the Absolute Privacy Plugin
Research Sucuri, 23 Feb 2012
We are seeing reports that a vulnerability in the Absolute Privacy WordPress plugin (link) is being used to hack and compromise sites with it installed. This plugin has a serious unpatched security vulnerability that allows anyone to log...
- New WordPress ToolsPack Plugin
Research Sucuri, 14 Feb 2012
We deal with many compromised sites daily and lately we are seeing something in common across many of the sites running WordPress. They have installed a plugin called ToolsPack ( ./wp-content/plugins/ToolsPack/ToolsPack.php), which accor...
- Sucuri SiteCheck - Web Malware Distribution - January 2012
Research Sucuri, 10 Feb 2012
As many know, we have been offering our free website malware scanner - Sucuri SiteCheck, since early in 2011. In our commitment to continue to give back to the community, we want to share some statistics. We’d like to share the distribut...
- Malware Redirecting To Enormousw1illa.com
Research Sucuri, 3 Feb 2012
We are seeing a large number of sites compromised with a conditional redirection to the domain http://enormousw1illa.com/ (194.28.114.102). On all the sites we analyzed, the .htaccess file was modified so that if anyone visited the site ...
- Better Engagement and Giving Back
Research Sucuri, 11 Jan 2012
Hi folks, we’re really excited about 2012, specifically because of our goal to give back more. This is in line with our core theme, to help the end-user better secure their environments. Things are not always perfect, but we strive to be...
- Ask Sucuri: Why Do I Only Get Malware Warnings on Certain Browsers?
Research Sucuri, 10 Jan 2012
A few days ago, our scanner alerted that a site had malware related to the Blackhole Exploit Kit. The owner of the site said that when he visited the site, nothing happened, and the malware wasn’t displayed - probably thinking it was a f...
- WordPress 3.3 XSS Vulnerability Patched (3.3.1 Released)
Research Sucuri, 3 Jan 2012
We just learned of a reflected XSS vulnerability in WordPress 3.3 via the comments form (wp-comments.php). It is explained in detail here. The disclosed vulnerability can only be triggered via Internet Explorer according to the disclosin...
- Blacklist Warnings for Users of the Stream-Video-Player WordPress Plugin
Research Sucuri, 27 Dec 2011
If you are using the plugin stream-video-player , it might be a good idea to disable this plugin for now. The plugin loads a Flash player from “http://rod.gs/_SVP/5.7.1896/player.swf?ver=1.3.2” , a domain (rod.gs) which is currently blac...
- Malware Being Called From Your php.ini File
Research Sucuri, 22 Dec 2011
Is your site infected with malware, and you can’t find it anywhere? It might be a good idea to search outside of your web directory, and look in your main configuration files (specially if you are on a dedicated/VPS server). We are seein...
- Ask Sucuri: How Long Does It Take For a Site To Be Removed From Google’s Blacklist? - Updated
Research Sucuri, 14 Dec 2011
If you have any questions about malware, blacklisting, or security in general, send it over to us: contact@sucuri.net and we will answer here. For all the “Ask Sucuri” answers, click here This is an update to our previous post about Goog...
- WordPress 3.3 is Out
Research Sucuri, 13 Dec 2011
For all our WordPress users, please remember to update to WordPress 3.3 that was just released. It should be a quick 1-click process in your dashboard, and nobody have an excuse not to do so. And if you are currently using any version be...
- The New (and Old) .htaccess Attacks - Now Using .in Domains
Research Sucuri, 28 Nov 2011
We have been talking about .htaccess redirections for a while. A site gets compromised and the attackers modify the .htaccess file(s) to redirect any search engine traffic to a different (malicious) page that attempts to compromise the b...
- Dre Armeda: WordPress End-User Security
Research Sucuri, 19 Nov 2011
Sucuri Co-Founder Dre Armeda did a great presentation at WordCamp Chicago about end-user security for WordPress users. Check out the video here: Dre will also be speaking at WordCamp Las Vegas 2011, make sure to say hi if you’re attendin...
- Htaccess Redirection to Sweepstakesandcontestsinfo dot com
Research Sucuri, 14 Nov 2011
Last week we started to see a large increase in the number of sites compromised with a .htaccess redirection to http://sweepstakesandcontestsinfo.com/nl-in.php?nnn=555 . This domain has been used to distribute malware for a while (genera...
- Timthumb.php Mass Infection - Aftermath - Part I
Research Sucuri, 28 Oct 2011
If you use WordPress you’re probably aware of the mass infection caused by a vulnerability in the timthumb.php script, a photo manipulation script included in many themes and plugins. Sites were compromised with anything from malware to ...
- MyBB web site and downloads compromised
Research Sucuri, 25 Oct 2011
It’s not good when your site gets infected with malware, specially if you’re a provider of software to many. If you are using MyBB (forum software), please be aware that their web site hacked and the software download packages compromise...
- Remove Unused/Testing/Debug Software From Your Site
Research Sucuri, 21 Oct 2011
We constantly see sites hacked due to vulnerabilities in various tools. In most cases, site owners don’t even realize they are there, or don’t even remember they were installed. For example, a site owner/manager has to make a quick modif...
- Evil backdoors - Part II
Research Sucuri, 14 Oct 2011
A few months ago we did a post about backdoors, explaining how they work and how to look for them. If you didn’t read it, take a read here: ASK Sucuri: What about the backdoors? However, we still see on online forums people recommending ...
- Mass infections from jjghui.com/urchin.js (SQL injection)
Research Sucuri, 12 Oct 2011
We are seeing many sites compromised with malware from jjghui.com/urchin.js. Most of them are IIS/ASP sites and the infection method seems to be similar to the Lizamoon mass infections from a few months ago (SQL injection). According to ...
- Malware on /etc/mailquota
Research Sucuri, 6 Oct 2011
We are seeing an interesting trend lately. A site gets compromised and starts to distribute malware to its users. The webmaster (owner of the site) searches everywhere for malicious strings, and can’t find anything. Where can it be hidde...
- Malware Infections from rebotstat dot com
Research Sucuri, 3 Oct 2011
We are starting to share some of our research and view of web-based malware online: http://sucuri.net/global. The #1 infection we are seeing in the last few days is caused by a heavily encoded piece of javascript malware: b=new function(...
- MySQL.com Hacked (Javascript Malware)
Research Sucuri, 26 Sep 2011
It looks like the MySQL.com website is currently hacked and compromised with a JavaScript malware (and serving malware to anyone visiting it). Our scanner identified the malware as mwjs159 which is often related to stolen FTP passwords. ...
- Mass compromise at inmotionhosting.com
Research Sucuri, 25 Sep 2011
Thousands of sites were defaced today at InMotion hosting. The defacement was made by “TiGER-M@TE” and all of the affected sites showed the following text: Server Hacked By TiGER-M@TE According to zone-h, they defaced at least 1,000 site...
- Website Getting Redirected? It Might Have Something To Do With Moneygram-tracking Dot Com
Research Sucuri, 21 Sep 2011
Have you ever tried to visit your site and you got redirected to a different site? Maybe some external news page that had nothing to do with your site? Then have you tried to visit it again to test and it worked properly? Over the last f...
- Mass Spam Infection From Wplinksforwork Dot Com (50k+ WordPress Sites Hacked)
Research Sucuri, 21 Sep 2011
Last year we spoke about the siteurlpath blackhat SEO attack that was infecting many WordPress sites with spam. But, how many? We had no clue at the time. Today, we decided to check on Google and it seems that almost 50k (yes, fifty thou...
- TimThumb.php backdoor
Research Sucuri, 14 Sep 2011
If your site got compromised lately with the TimThumb.php vulnerability, make sure to check that script to see if it was not modified to act as a backdoor as well. We are seeing in many sites the timthumb.php with the following code adde...
- ASK Sucuri: What About the Backdoors?
Research Sucuri, 9 Sep 2011
If you have any question about malware, blacklisting, or security in general, send it to us: contact@sucuri.net and we will answer here. Question: What about the backdoors? Why are they so hard to find? How do you guys find them? When a ...
- Ascio Registrar Compromised - Brings Down UPS.com, Theregister and Others
Research Sucuri, 4 Sep 2011
If you tried to visit today the sites for UPS.com, theregister.co.uk, Vodafone, The Daily Telegraph and some other high profile sites, you would have received a scary message saying that they’ve been hacked (by turkguvenligi): And they w...
- TimThumb.php Attacks - Now Being Used for Blackhat Spam SEO and Might Break Your Site
Research Sucuri, 25 Aug 2011
We have been talking a lot lately about the Timthumb.php vulnerability and the importance of updating that script as soon as possible. Sites that didn’t update it are getting compromised very easily. We explained it in more detail here: ...
- TimThumb.php attacks - Now using googlesafebrowsing dot com
Research Sucuri, 24 Aug 2011
We have been talking a lot lately about the Timthumb.php vulnerability and the importance of updating the script as soon as possible. Sites that didn’t update it are getting compromised very easily. We explained it in more detail here: M...
- Mass Infection of WordPress Sites Due to TimThumb ( counter-wordpress dot com )
Research Sucuri, 23 Aug 2011
Many people are asking us about this “counter-wordpress.com” type of malware, so we will post some details here. Our scanner has been identifying it for a while, so if you think your site is compromised, just check it in there. So first,...
- Attacks Against Timthumb.php in the Wild - List of Themes and Plugins Being Scanned
Research Sucuri, 18 Aug 2011
We are seeing large scale attacks against the vulnerable timthumb.php script in the wild. Thousands of sites are getting compromised and if you have it in your WordPress site, you better get it fixed right now! After a few days analyzing...
- WordPress sites with .htaccess hacked
Research Sucuri, 17 Aug 2011
The TimThumb.php vulnerability is causing a lot of WordPress sites to get compromised with the superpuperdomain.com and superpuperdomain2.com remote JavaScript injection. However, that’s not all that it is doing. On many of the sites we ...
- TimThumb.php Vulnerability Not Only Affecting Themes - Plugins too
Research Sucuri, 16 Aug 2011
The Timthumb.php vulnerability is being used in the wild to hack and infect thousands of WordPress sites. Hopefully everyone is checking their themes and updating the script to make sure it is not vulnerable. This is wishful thinking. Un...
- Non-Stop Attacks Against osCommerce - Time to Take Action
Research Sucuri, 16 Aug 2011
The malware attacks against osCommerce sites are still going at full force and the site owners have to take action to secure and update their sites as soon as possible. Think about that, with so many valuable targets (online stores) that...
- Update to the Superpuperdomain2.com malware
Research Sucuri, 15 Aug 2011
Just a quick update to the Superpuperdomain2.com/Superpuperdomain.com malware infection that has been affecting thousands of WordPress sites with the vulnerable timthumb.php script. You can read more about it here: https://blog.sucuri.ne...
- WordPress Sites Hacked with Superpuperdomain2.com
Research Sucuri, 14 Aug 2011
A few days ago we posted about a series of attacks that were happening against WordPress sites running the vulnerable timthumb.php script. We detected thousands of sites compromised with it and now are are seeing a small change in the ma...
- WordPress Sites Hacked with Superpuperdomain dot com (Attacking Timthumb.php)
Research Sucuri, 11 Aug 2011
We are seeing a large number of WordPress sites compromised with a malicious JavaScript loading from superpuperdomain.com/count.php. That JavaScript redirects visitors that were going to the WordPress site to fake search engines. This is...
- Attacks against osCommerce sites - Spam / google_analytics_obh
Research Sucuri, 9 Aug 2011
It seems that the attacks against osCommerce are not going to stop any time soon. With so many valuable targets (online stores) that are not updated and secured, why would they? *If you have an osCommerce site, please follow these steps ...
- Mass Compromise of Sites at gogvo.com - SEO Spam
Research Sucuri, 4 Aug 2011
A regular topic of discussion the past few months has been the basicpills link injection (a type of blackhat seo spam) on WordPress sites. If you are not familiar with it, thousands of sites have been infected with basicpills which injec...
- Timthumb Security Vulnerability - List of Themes
Research Sucuri, 3 Aug 2011
The Timthumb 0-day security vulnerability is generating a lot of noise and for good reason. If you have a theme that includes TimThumb, your site can be easily hacked. Because of this, we checked the WordPress Free Themes Directory and a...
- Keeping Your WordPress Themes Updated
Research Sucuri, 2 Aug 2011
We talk a lot about keeping WordPress and the plugins you use updated. That’s great and all, but you also have to remember that it doesn’t stop there, you have to keep your themes updated as well. Recently we found that some very old ver...
- Timthumb.php Security Vulnerability - Just the Tip of the Iceberg
Research Sucuri, 2 Aug 2011
There has been some buzz about a zero day vulnerability found in Timthumb.php that can allow for arbitrary file uploads. Although this is a platform independent issue, it is specially an issue on WordPress where a lot of theme authors ch...
- Host4africa Mass Compromise
Research Sucuri, 2 Aug 2011
We are seeing a lot of sites hosted at host4africa.com compromised with Blackhat Spam SEO. Most of them are in the .co.za TLD (at 74.53.0.0/16 and 74.54.0.0/16) and have hidden links to generic drugs (common Pharma Spam). When you on cli...
- The Danger of Remote Widgets - Feedcat.net Sold and Now Distributing Malware
Research Sucuri, 28 Jul 2011
Do you like to add all types of “widgets” and cool badges to your site? Be careful which ones do you choose, or your site may get compromised. Be specially careful if the widget vendor sells the technology and doesn’t inform its users. W...
- Top linked sites - What webmasters are linking to
Research Sucuri, 27 Jul 2011
We scan hundreds of thousands of sites daily here at Sucuri and while analyzing some of the data we got interested on what sites are getting the “link love” more often. By link love, I mean what “do follow” links most webmasters have in ...
- Python: No such file or directory - Your site is likely compromised
Research Sucuri, 18 Jul 2011
If you run a WordPress site and you are seeing the following error at the top of your pages: sh: /usr/local/bin/python: No such file or directory It means that it is likely compromised. How do we know that? We were tracking a large black...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.