HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,880 reports kept since 2009. Updated automatically every 10 minutes. Last checked 1 min ago.
- Python: No such file or directory - Your site is likely compromised
Research Sucuri, 18 Jul 2011
If you run a WordPress site and you are seeing the following error at the top of your pages: sh: /usr/local/bin/python: No such file or directory It means that it is likely compromised. How do we know that? We were tracking a large black...
- Google blocks .co.cc, attackers are now using .co.tv
Research Sucuri, 6 Jul 2011
It is being reported that Google took action against the high number of malware sites in the .co.cc domain, removing more than 11 million sites from their search results. For us this is good news, since we haven’t been seeing anything go...
- WordPress 3.2 and PHP support - Security effect
Research Sucuri, 4 Jul 2011
WordPress 3.2 is going to be released very soon and one of the biggest changes is that they will drop support for PHP4 and all versions of PHP5 bellow 5.2.4. WordPress.org has provided some informative posts about their reasons for dropp...
- WordPress 3.1.4 available - Time to update
Research Sucuri, 30 Jun 2011
If you are running WordPress, it is time to update it now. WordPress v3.1.4 was just released with security fixes for all the previous versions (specially important with you have users with the editor-level permissions): From the WordPre...
- WP-phpmyadmin WordPress plugin - Delete it now
Research Sucuri, 23 Jun 2011
If you are using the WP-phpmyadmin WordPress plugin, delete it now. We are seeing multiple sites getting hacked through it and we are investigating what is going on. On all the sites we’ve analyzed, the following code was found inside th...
- WordPress plugins hacked - Understanding the backdoor
Research Sucuri, 22 Jun 2011
If you haven’t heard about it already, yesterday three popular WordPress plugins (AddThis, WPtouch, and W3 Total Cache) had a malicious backdoor added to them via the plugin repository. That lead to WordPress.org resetting all passwords ...
- Backup, backup and backup
Research Sucuri, 22 Jun 2011
We just heard of a sad story about an Australian web hosting company (Distribute.IT) that was hacked and all of the sites they hosted were deleted (almost 5 thousand of them). What’s even worse is that the attackers deleted and corrupted...
- Google blacklisted all the .cz.cc domains
Research Sucuri, 16 Jun 2011
It seems that Google just blacklisted all the sites under the .cz.cc main domain (including the nic.cz.cc, start.cz.cc and all others). In their status page Google says: Has this site acted as an intermediary resulting in further distrib...
- Information Leakage on multiple WordPress themes by WooThemes
Research Sucuri, 6 Jun 2011
This weekend there was a post on the Full disclosure list about multiple vulnerabilities on some WordPress themes by WooThemes. This is what the message said: Vulnerable are the next themes by WooThemes: Live Wire (all three themes from ...
- Sony Music Brazil hacked (yet another sony defacement)
Research Sucuri, 5 Jun 2011
I hate to pick on Sony, but they got hacked again (and no, I am not talking about the Lulzsec + sonypictures, this is another one). This time was Sony Music Brazil, which was defaced yesterday night and STILL is defaced after more than 1...
- Links Injection on WordPress - Blackhat SEO Spam (basicpills) update
Research Sucuri, 3 Jun 2011
For the last few months we’ve been tracking a very large blackhat SEO spam campaign initiated by basicpills.com, and many other pharma-related domains (mostly located at 212.117.161.190 and 212.117.168.214). The method used is very simpl...
- Understanding .htaccess attacks - Part 1
Research Sucuri, 27 May 2011
Attackers have been using the .htaccess file for a while. They use this file to hide malware, to redirect search engines to their own sites (think blackhat SEO), and for many other purposes (hide backdoors, inject content, to modify the ...
- WordPress 3.1.3 available (security fixes)
Research Sucuri, 25 May 2011
If you are using WordPress, make sure to upgrade it now. The version 3.1.3 was just released with a few security fixes: * Various security hardening by Alexander Concha. * Taxonomy query hardening by John Lamansky. * Prevent sniffing out...
- LizaMoon SQL injections (ur.php) - Now vcvsta.com, asweds.com, etc.
Research Sucuri, 25 May 2011
A couple of months ago the Lizamoon malware / Mass SQL injection was getting a lot of news coverage that it could be affecting hundreds of thousands of sites. The media mostly forgot about it, but we kept tracking those attacks and they ...
- osCommerce malware: Cannot redeclare corelibrarieshandler
Research Sucuri, 20 May 2011
We have been posting for a while about attacks targeting and infecting thousands of osCommerce sites (CreateCSS, div_colors, etc) and the importance of keeping it updated and secure. If you think things have been improving, just for the ...
- Ask Sucuri: Why Does My Site Keep Getting Reinfected?
Research Sucuri, 11 May 2011
If you have any question about malware, blacklisting, or security in general, send it to us: contact@sucuri.net and we will answer here. Question: Why does my site keep getting hacked / reinfected? A lot of our new customers only get in ...
- LastPass hacked? Forcing users to change their master passwords
Research Sucuri, 5 May 2011
If you are a LastPass user, you will be forced to change your master password in order to continue using the service. We just read some worrying news that they might be hacked. Yes, “might”. It is more worrying because they don’t know fo...
- Are WordPress users taking care of their security? State of Blog Security - Part I
Research Sucuri, 5 May 2011
Almost two years ago we published an article on the “state of blog security” (focused on WordPress) where we checked the percentage of blogs that were taking care of their security properly. We checked if they had WordPress updated and a...
- WP-DBManager Security update (serious issue)
Research Sucuri, 5 May 2011
Just a quick note that if you are using the WordPress WP-DBManager plugin, make sure to update it as soon as possible. Old versions of the plugin ( Continue reading WP-DBManager Security update (serious issue) at Sucuri Blog.
- TheWebbyAwards hacked and compromised with Blackhat SEO
Research Sucuri, 4 May 2011
The WebbyAwards web site ( www.webbyawards.com/ ) is currently hacked and compromised with Blackhat SEO. If you try to search for it on Google you will get a warning saying that “This site may be compromised”: And if you look at the sour...
- WordPress 3.1.2 released - Security fixes
Research Sucuri, 27 Apr 2011
The WordPress team just released a new version of WordPress (3.1.2) to fix a security issue where contributor-level users were allowed to publish posts. It is a small release, and everyone using WordPress should upgrade to it! From the W...
- Jquery4html.co.cc - Malware update - Fake AV Redirections
Research Sucuri, 27 Apr 2011
Weekly (kinda daily) malware update. You can track all our updates by following our malware_updates category. *If your site has been affected with any of these issues, contact us at support@sucuri.net or visit http://sucuri.net to get he...
- Mass infections - globalpoweringgathering.com
Research Sucuri, 25 Apr 2011
We first detected malware from globalpoweringgathering.com almost a month ago, and posted on our blog about it. But in the last few days, we started to see a big increase in the number of sites infected with it. We were able to catalog a...
- CBS Money Watch / ZDnet hacked and blacklisted by Google
Research Sucuri, 20 Apr 2011
We are getting reports that the CBS Money Watch and some ZDNet web sites are currently distributing malware and blacklisted by Google. We are still investigating it, but if you try to visit the CBS Money watch site (moneywatch.com), you ...
- Ask Sucuri: What is the Most Common Type of Malware Out There?
Research Sucuri, 15 Apr 2011
If you have any questions about malware, blacklisting, or security in general, send it to us: contact@sucuri.net and we will answer here. For all the “ask sucuri” answers, go here. Question: What is the most common type of malware (on we...
- CreateCSS malware update
Research Sucuri, 15 Apr 2011
We have been talking about this CreateCSS malware for a little while, but recently we started to see a shift on how the attackers are using it. *If you don’t remember what it is, the CreateCSS malware has been used to infect thousands of...
- Automattic / WordPress hacked - Security incident
Research Sucuri, 13 Apr 2011
The guys from Automattic (WordPress) posted today a brief statement about a security incident that they suffered. Tough note to communicate today: Automattic had a low-level (root) break-in to several of our servers, and potentially anyt...
- Link injection on hacked WordPress sites - Blackhat SEO spam
Research Sucuri, 11 Apr 2011
The last few months we’ve been tracking, and helping webmasters affected by a very large blackhat SEO spam campaign initiated by basicpills.com, and many other domains located at 212.117.161.190. This campaign has infected thousands of W...
- Database Injection on Joomla Websites - yourstatscounter dot cz dot cc
Research Sucuri, 6 Apr 2011
It seems that a good amount of Joomla sites are being infected with malware from the infamous “.cc” domains. All of the hacked sites have the malicious code injected directly in to their databases (SQL injection), via an unknown source (...
- WordPress 3.1.1 is available (security fixes)
Research Sucuri, 5 Apr 2011
There is a new version of WordPress available (3.1.1) that includes multiple security fixes. These are the changes according to WordPress.org: Some security hardening to media uploads, performance improvements, fixes for IIS6 support and...
- Continuing attacks against osCommerce: khcol.com
Research Sucuri, 5 Apr 2011
Busy week for osCommerce in terms of malware. First, the div_colors string, then, the CreateCSS string, and now, we are seeing thousands of osCommerce sites infected with a malware pointing to http://khcol.com . This is how it looks like...
- LizaMoon Mass SQL injection (ur.php) - Updates
Research Sucuri, 4 Apr 2011
There has been a lot of talk for the last few days about a mass sql injection targeting IIS/ASP.net sites. Those attacks has been going for a while and the lizamoon.com/ur.php is not the only domain being used to distribute the malware, ...
- Ask Sucuri: How Long To Remove Google’s Blacklist?
Research Sucuri, 3 Apr 2011
If you have any questions about malware, blacklisting, or security in general, send it to us: contact@sucuri.net and we will answer here. For all the “ask sucuri” answers, go here Question: My site was hacked and we cleaned and secured i...
- Database injection, lessthenaminutehandle.com and more updates
Research Sucuri, 1 Apr 2011
We posted a few weeks ago about a large scale database injection attack affecting WordPress on shared hosts. The infected sites got the following javascript malware inserted on every post of their database (generally the wp-post table on...
- APRIL FOOLS: No Serious Security Vulnerability on WordPress 3.x - Remote Command Execution
Research Sucuri, 1 Apr 2011
This post was not real. It was an attempt at humor, as bad as it may seem. The post has been removed, and we understand the concerns. We truly apologize for misleading anyone. There is no vulnerability with WordPress 3.x. WordPress and i...
- The “div_colors” Malware Update
Research Sucuri, 30 Mar 2011
We are still seeing a big growth in the number of sites infected with the div_colors malware string. In fact, the osCommerce forums are full of people asking about it, uncertain what to do, and what it does. So, what is this div_colors s...
- Will Google blacklist itself?
Research Sucuri, 29 Mar 2011
We were analyzing an infected site today and their Google blacklist diagnostic said the following: Has this site hosted malware? Yes, this site has hosted malicious software over the past 90 days. It infected 3 domain(s), including site....
- Malware week: The div_colors, CreateCSS and others
Research Sucuri, 28 Mar 2011
We are starting to see an interesting trend regarding how the latest web-based malware is being distributed. Instead of heavily encoding the malicious code on the infected web sites, attackers are now trying to make it look like legitima...
- Database injection and lessthenaminutehandle.com - Intermediary domains
Research Sucuri, 22 Mar 2011
We posted a few days ago about a large scale database injection attack affecting shared hosts. The infected sites got the following javascript malware inserted on every post of their database (generally the wp-post table on WordPress): e...
- Attacks against IIS/ASP sites - alisa-carter dot com
Research Sucuri, 21 Mar 2011
Over the last few days, we’ve seen a number of sites getting hacked with a malware script pointing to http://alisa-carter.com/ur.php . It is done using the same SQL injection attack as used in therobint-us mass infection a few months ago...
- Tumblr mistake or security issue
Research Sucuri, 19 Mar 2011
There is a post on Hacker News about a possible security issue with Tumblr. Basically a lot of confidential information, including server IPS, API keys, passwords, etc were leaked. Here is some of the stuff that was disclosed: Database::...
- Database injection, Hilary Kneber and lessthenaminutehandle dot com
Research Sucuri, 17 Mar 2011
We posted a few weeks ago about a database injection attack that infected thousands of WordPress blogs on shared hosts. At that time, the attackers were inserting a javascript link pointing to welcometotheglobalisnet.com/js.php?kk=25 in ...
- Solution for the link injection spam from basicpills
Research Sucuri, 16 Mar 2011
We recently posted about a large scale blackhat SEO campaign by basicpills that infected thousands of WordPress sites over the last few weeks. A lot of people contacted us for help and asked for directions on how to remove those links fr...
- Link injection, basicpills dot com and Blackhat SEO spam
Research Sucuri, 12 Mar 2011
For the last few weeks we’ve been tracking a very large blackhat SEO spam campaign initiated by basicpills.com, generic-ed-pharmacy.com, getrxpills.com and a few other domains (all located at 212.117.161.190). They basically infected tho...
- Malware week - 0133.0331.0242.0033, javadisplay and more
Research Sucuri, 10 Mar 2011
Very busy week in terms of malware. First Hilary Kneber decided to make a come back, inlovebot.com and crazymasya.com reinfected a lot of sites, and now many outdated Joomla sites are being infected with malware from 0133.0331.0242.0033 ...
- Hilary Kneber Again - welcometotheglobalisorg
Research Sucuri, 10 Mar 2011
We are seeing (again) a number of sites infected with a variation of the welcometotheglobalisnet.com malware string that appeared a few weeks ago. The details are the same as in the previous post except that now they are using welcometot...
- Chase phishing - case study
Research Sucuri, 8 Mar 2011
Last week we were called to fix a Joomla site that was infected by malware and disabled by their hosting company. The user forwarded the email he received: Your account was reported to us by Google for malicious content and has been deac...
- Brenz.pl is Back With Malicious iFrames
Research Sucuri, 5 Mar 2011
We used to see brenz.pl being used to distribute malware back in 2009, and got shut down. However, for the last few weeks we noticed a big increase in the number of sites infected with iframes pointing to it. All the sites infected have ...
- Alexa TOP 100k Sites - The Malware Blues
Research Sucuri, 3 Mar 2011
How big do you think the web-based malware problem is? How many sites do you think were hacked and/or infected with malware in the last 6 months? How many of those got blacklisted by Google? The numbers could have been better for the Ale...
- Grameen Bank web site hacked / infected with spam
Research Sucuri, 2 Mar 2011
The Grameen Bank is in the news today after one of its founders, Muhammad Yunus, was fired from it. You can see the news about it here. Leaving the politics aside, what interested us is that their main web site is currently hacked and in...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.