Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,880 reports kept since 2009. Updated automatically every 10 minutes. Last checked 5 min ago.

  1. Yet Another WordPress Security Post - Part Two

    Research Sucuri, 2 Mar 2011

    We deal with hacked sites on a daily basis and one of the most common questions we get is how to avoid getting hacked again. The simple answer to this question is to to minimize your risk online as best as possible. To help you better ap...

  2. Alexa top sites - Blacklist for January/2011

    Research Sucuri, 26 Feb 2011

    Every month we analyze Alexa’s TOP 1 million site ranking and correlate that data with Google’s blacklist. Our goal is to get an overall view of the sites that are getting hacked, blacklisted, etc. For Jan-2011, the number is pretty stan...

  3. The attack from the .cc’s domains

    Research Sucuri, 25 Feb 2011

    Over the last few days we’ve continued to see a large increase in the number of sites hacked and infected with a malicious iframe from .co.cc (.vv.cc, .cz.cc, etc) domains. You can run a free scan using SiteCheck to see if you’ve been in...

  4. Hilary Kneber Strikes Again - welcometotheglobalisnet

    Research Sucuri, 19 Feb 2011

    It seems that after a few months quiet, the “Hilary Kneber” group is back at it again. Their latest approach is very typical of Hilary Kneber style attacks affecting GoDaddy shared hosts. Basically they modify every PHP file and the data...

  5. UCalgary web sites compromised with spam

    Research Sucuri, 17 Feb 2011

    We were cleaning up a compromised site today (with the unfamous pharma hack), when we saw multiple spam links in the hacked site pointing to ucalgary.ca (big Canadian university). What was interesting is that it was not pointing to a sma...

  6. Cleaning up an infected website - Part I: WordPress and the Pharma Hack

    Research Sucuri, 16 Feb 2011

    New release! On 11/03/2017 everything you need to know on how to secure your WP site came out and it includes best practices and a list of vulnerabilities. Read it now! Updated: 9/14/2016 Pharma hacks continue to evolve, our latest artic...

  7. Thailand official foreign affairs / embassy web sites hacked

    Research Sucuri, 16 Feb 2011

    The Royal Thai (Thailand’s) consulate and embassy web sites (part of their foreign affairs ministry) are currently hacked and infected with a lot of spam (of the pharmacy kind). Their web site is located at http://www.mfa.go.th and with ...

  8. Large Blackhat SEO SPAM Campaign Targeting Joomla Sites

    Research Sucuri, 15 Feb 2011

    We are seeing a large number Joomla sites hacked and being used in a blackhat SEO SPAM campaign consisting of thousands of infected web sites. Most of them are small and using vulnerable and old versions of Joomla (1.0 and This is how th...

  9. Weekly Malware Update - 2010/Feb/11

    Research Sucuri, 11 Feb 2011

    Weekly malware update. You can track all updates by following our malware_updates category. *If your site has been affected with any of these issues, contact us at support@sucuri.net or visit http://sucuri.net to get help or if you want ...

  10. Something is wrong at WordPress.com / CNN.com

    Research Sucuri, 11 Feb 2011

    Update: The problem is now fixed, seems to be caused by a redirection error. Many of the (CNN) VIP sites at WordPress.com are redirecting to: http://superfantastically.com/. It includes politicalticker.blogs.cnn.com, popwatch.ew.com, tec...

  11. WordPress 3.0.5 is available (with security fixes)

    Research Sucuri, 8 Feb 2011

    If you use WordPress, we recommend updating to the latest version (3.0.5) as soon as possible, specially if you have multiple users with authoring/contributing roles. This is the summary from WordPress.org: This security release is requi...

  12. Weekly malware update - 2010/Jan/31

    Research Sucuri, 1 Feb 2011

    Weekly malware update. You can track all updates by following our malware_updates category. *If your site has been affected with any of these issues, contact us at support@sucuri.net or visit http://sucuri.net to get help or if you want ...

  13. Backdoor: No malware on this code, you can check it by yourself

    Research Sucuri, 1 Feb 2011

    We were cleaning up an infected web site a few days ago and it had multiple backdoors. They all started like that: // ketek90@gmail.com // no malware on this code, you can check it by yourself ; - ) We see this very often, where malware ...

  14. SourceForge.net servers compromised

    Research Sucuri, 28 Jan 2011

    If you have an account on SourceForge, or host any project in there, we recommend that change your password ASAP (especially if you re-use it somewhere else). Plus, if you host anything on their servers, make sure all of your files are c...

  15. What to Do When Your Site Gets Blacklisted

    Research Sucuri, 27 Jan 2011

    Most site owners only start to think about security when their site gets hacked (infected with malware) and consequently blacklisted by Google with a malware warning to visitors. So, here is what you need to do once you find out that you...

  16. Malware update: .co.cc malicious entries

    Research Sucuri, 21 Jan 2011

    For the last weeks (actually months), we’ve been tracking a large number of malware from .co.cc domains. It seems that every .co.cc domain we find is being used to host either malware or spam. One of the techniques we are seeing to sprea...

  17. Weekly malware update - 2010/Jan/14

    Research Sucuri, 17 Jan 2011

    Weekly malware update. You can track all updates by following our malware_updates category. *If your site has been affected with any of these issues, contact us at support@sucuri.net or visit http://sucuri.net to get help or if you want ...

  18. OpenX.org serving malware?

    Research Sucuri, 7 Jan 2011

    We are tracking a few sites that are currently blacklisted and showing a warning from Google that openx.org (home of a popular open source ad server) is the site responsible for the infection: 2 domain(s) appear to be functioning as inte...

  19. Alexa top sites - Blacklist for December/2010

    Research Sucuri, 7 Jan 2011

    Every month we analyze Alexa’s TOP 1 million site ranking and correlate that data with Google’s blacklist. Our goal is to get an overall view of the sites that are getting hacked, blacklisted, etc. For Dec-2010, the number is pretty stan...

  20. Weekly malware update - 2010/Jan/07

    Research Sucuri, 7 Jan 2011

    Weekly malware update. You can track all updates by following our malware_updates category. *If your site has been affected with any of these issues, contact us at support@sucuri.net or visit http://sucuri.net to get help or if you want ...

  21. Weekly malware update - 2010/Dec/17

    Research Sucuri, 17 Dec 2010

    Starting this week, we’re going to begin posting a weekly malware update about the issues (always malware-related ) that arise throughout the week. This is the first one and you will be able to track those by following our malware_update...

  22. Analysis of the Gawker compromise

    Research Sucuri, 14 Dec 2010

    As most of you probably know, Gawker media’s servers were compromised, resulting in a security breach at Lifehacker, Gizmodo, Gawker, Jezebel, io9, Jalopnik, Kotaku, Deadspin, and Fleshbot. It means that if you’ve ever had an account on ...

  23. Malware update: publifacil.org - htaccess changes and PE*.php

    Research Sucuri, 10 Dec 2010

    The last few days we’ve been tracking a large number of sites infected with a very interesting piece of malware. All the sites hacked so far contain the following in their .htaccess file (PEcasas.php could be many names like PEtherm.php,...

  24. WordPress 3.0.3 released (security update)

    Research Sucuri, 8 Dec 2010

    Running WordPress? Time to update it again! Version 3.0.3 has been released fixing some security vulnerabilities. If you can’t upgrade, make sure to disable remote publishing by going to the page “Settings → Writing” to see if it is disa...

  25. WordPress 0 day exploit (version 3.0.1 and older)

    Research Sucuri, 5 Dec 2010

    We posted last week about the release of WordPress 3.0.2 that fixes a few security vulnerabilities. Today, full details of the vulnerability and exploit code have been released. So if you haven’t upgraded yet, make sure to do so now (spe...

  26. Alexa top sites - Blacklist for November

    Research Sucuri, 4 Dec 2010

    Every month we analyze Alexa’s TOP 1 million site ranking and correlate that data with Google’s blacklist. Our goal is to get an overall view of the sites that are getting hacked, blacklisted, etc. For Nov-2010, the number is pretty stan...

  27. WordPress 3.0.2 released (security update)

    Research Sucuri, 30 Nov 2010

    If you’re using WordPress, make sure and update to the latest version (3.0.2) as soon as possible. Especially if you have multiple authors with access to your blog/site. Details about the security issue fixed: This maintenance release fi...

  28. Savannah.gnu.org hacked and currently offline

    Research Sucuri, 30 Nov 2010

    We’ve learned that savannah.gnu.org (used as a central code repository for many GNU projects - gcc, etc) has been hacked and is currently offline. They posted some details on their site explaining what is going on: savannah.gnu.org Savan...

  29. Yet Another WordPress Security Post - Part One

    Research Sucuri, 30 Nov 2010

    At the end of October we had the opportunity to attend WordCamp Las Vegas. WordCamp’s are great events organized in various cities/countries by the WordPress community to discuss, learn, and teach all things WordPress. If you’ve never at...

  30. Secunia defaced? DNS hijacked?

    Research Sucuri, 25 Nov 2010

    Secunia is a very popular security company, specialized in vulnerability intelligence, security management, and things like that. However, yesterday evening, everyone visiting their site received a special “defaced” message (“System down...

  31. osCommerce attacks and nt07.in, nt06.in, etc

    Research Sucuri, 20 Nov 2010

    We posted yesterday about a series of attacks against osCommerce sites using some russian domains to push the malware (generally the fake AV). We also posted details on how to fix and secure osCommerce to protect against those: https://b...

  32. Continuing attacks against osCommerce sites

    Research Sucuri, 19 Nov 2010

    We are seeing an increase in the number of osCommerce sites hacked lately, and we recommend anyone using it to take precautions to avoid getting hacked and/or reinfected. On most of the sites we’ve analyzed so far, the attackers used the...

  33. Malware update: inininininininin.in (and oscommerce)

    Research Sucuri, 6 Nov 2010

    Quick malware update: We are seeing many osCommerce sites infected with malware managed by inininininininin.in, comcomcomcomcomcom.com and a few others. All the domains involved are hosted at 91.204.48.45. These domains were registered b...

  34. Alexa top sites - Blacklist for October

    Research Sucuri, 3 Nov 2010

    Every month we analyze Alexa’s TOP 1 million site ranking and correlate that data with Google’s blacklist. Our goal is to get an overall view of the sites that are getting hacked, blacklisted, etc. For OCT-2010, the number is pretty stan...

  35. Hilary Kneber at it again: voip.dialistico.net

    Research Sucuri, 26 Oct 2010

    The Hilary Kneber group is at it again. We are now tracking their usage of voip.dialistico.net to push malware to quite a few sites. If you don’t know about them, just take a look at our blog history. Most of the mass attacks we posted w...

  36. Malware update: ssl-verification.net

    Research Sucuri, 22 Oct 2010

    Quick malware update: The site ssl-verification.net (nice name) is being used to distribute SEO spam and malware (the famous fake AV). We recently wrote about the domain ssl-validation, but it seems that they disabled it and are using ss...

  37. More attacks - Hilary Kneber and insomniaboldinfocom.com

    Research Sucuri, 21 Oct 2010

    For the last couple of days, we’ve been seeing a good number of sites hacked with a familiar pattern. All of them have a javascript loading malware (the famous fake AV) from: http://insomniaboldinfocom.com/mm.php http://insomniaboldinfon...

  38. NASA web site hacked and serving malware/spam

    Research Sucuri, 21 Oct 2010

    Some sites under NASA’s Jet Propulsion lab ( http://jpl.nasa.gov/ ) have been hacked and are being used on the infamous blackhat SEO Spam network. Not only that, but they are also serving malware to unsuspicious users. The sites in quest...

  39. Kaspersky site hacked and redirecting users to fake AV

    Research Sucuri, 19 Oct 2010

    If you tried to download and/or visit Kaspersky’s web site yesterday, please check if your computer didn’t get infected. Their web site was hacked and their download pages were redirecting users to a fake AV (malware) page. The malware w...

  40. Rail Europe trying to sell me Amoxicillin - Pharma hack

    Research Sucuri, 13 Oct 2010

    I was looking to buy some Amoxicillin online today and didn’t want to get a prescription. So I went to Google and searched for it. Interesting enough, Rail Europe ( https://blog.raileurope.com ) was the first result. Ok, so I’m kidding, ...

  41. osCommerce attacks - kirm-sky.ru

    Research Sucuri, 12 Oct 2010

    We are seeing a very large number of osCommerce sites hacked on the last few days. If you are an osCommerce user, make sure to update it asap and check if to see if it’s been infected (also remove the file_manager.php from the admin dire...

  42. More attacks - Hilary Kneber and meqashoppecom - Part II

    Research Sucuri, 10 Oct 2010

    A few days ago we reported a large scale attack affecting WordPress sites at hosted on 123-reg servers. They were using the domains meqashopperinfo.com and meqashopperonline.ccom to spread the malware. You can read more about it here. To...

  43. EA.com - Please protect your forum or shut it down

    Research Sucuri, 8 Oct 2010

    A note to EA.com: Please protect your forums or shut it down. Not only are more than half of the posts (http://forum.ea.com) serving SPAM, they are also being used to affect other web sites. More often than not, when a site gets hacked w...

  44. Alexa top sites - Blacklist status for september

    Research Sucuri, 7 Oct 2010

    Every month we analyze Alexa’s TOP 1 million site ranking and correlate that data with Google’s blacklist. Our goal is to get an overall view of the sites that are getting hacked, blacklisted, etc. For SEP-2010, the number is pretty stan...

  45. More attacks - Hilary Kneber and meqashopperinfo.com

    Research Sucuri, 4 Oct 2010

    Update: This attack seems to be restricted to 123-reg: www.123-reg.co.uk The last couple of days, we’ve been seeing a good number of sites hacked with a familiar pattern. All of them have a javascript loading malware (the famous fake AV)...

  46. Attack against IIS/ASP sites - google-stat50.info

    Research Sucuri, 28 Sep 2010

    A large number of sites have been hacked again in the last few days with a malware script pointing to google-stat50.info (and google-stats50.info) . Not only small sites, but some big ones got hit as well. It is the same SQL injection at...

  47. OpenX users - Time to upgrade

    Research Sucuri, 16 Sep 2010

    *Note that openx.org is currently offline, so we recommend disabling it until you can upgrade. **We are mirroring version 2.8.7 here: http://sucuri.net/openx-2.8.7.tar.gz if you don’t want to wait until openx is back online. ***If your s...

  48. Blackhat SEO Spam C&C: wseow and seotoos up to no good!

    Research Sucuri, 15 Sep 2010

    We have been tracking these Blackhat SEO Spam C&C (command and control) servers for a while and thought it would be a good time to expose some of the details. They have been actively trying to exploit blogs using old versions of WordPres...

  49. ASIS International Website Blacklisted by Google

    Research Sucuri, 10 Sep 2010

    The official website (asisonline.org) of ASIS International, a major physical security association was hacked and blacklisted yesterday. Add another case to the list of sites using outdated and/or vulnerable applications. In the case of ...

  50. Success Magazine Blog Hit With Malware

    Research Sucuri, 8 Sep 2010

    We were analyzing some hacked sites today and one of them was full of SPAM. After some digging, we found that it was loading the Blackhat SEO Spam from blog.success.com (the official blog of Success Magazine). We conducted a quick scan o...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support