Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,880 reports kept since 2009. Updated automatically every 10 minutes. Last checked 5 min ago.

  1. Modx and the new gcounter.cn attack

    Research Sucuri, 7 Sep 2010

    Quick malware update. See all the latest ones here. We are seeing lately many sites running Modx that are infected with a malware getting loaded from the file /manager/includes/document.parser.class.inc.php . We don’t know yet how the si...

  2. Malware update - ssl-validation.net

    Research Sucuri, 3 Sep 2010

    Quick malware update: The site ssl-validation.net (nice name) is being used to distribute SEO spam and malware (Rhe famous fake AV, say it ain’t so). You can get details of the code being used here: http://sucuri.net/?page=tools&title=bl...

  3. Malware update - seconeo.com,secowo.com,etc

    Research Sucuri, 3 Sep 2010

    We will be posting some quick malware updates on our blog from now on. If your WordPress site got hacked with malware from any of these domains: http://ae.awaue.com http://ie.eracou.com http://ao.euuaw.com http://aeaaea.com/ou http://sec...

  4. Malware update - Alex Bodrov - awaue.com,etc

    Research Sucuri, 31 Aug 2010

    We will be posting some quick malware updates on our blog from now on. The latest one that is affecting quite a few sites are malicious javascripts being injected directly into the wp-posts table on WordPress sites. Those are the domains...

  5. Hilary Kneber (part XI) - sippa.dottasink.net

    Research Sucuri, 24 Aug 2010

    Hilary Kneber (hilarykneber@yahoo.com) is at it again. We’ve been detecting various sites infected with a malicious javascript pointing to http://sippa.dottasink.net: This redirects any visitor of the hacked site to http:// www3.pc-clean...

  6. Pharma hack and their C&C (Command & control) server

    Research Sucuri, 12 Aug 2010

    A large portion of the sites Sucuri has been fixing in recent weeks are stemming from infections caused by the infamous Pharma Hack. We posted a detailed document explaining how to fix it and clean the attack: Understanding and cleaning ...

  7. Cleaning the “siteurlpath” hack on WordPress (wplinksforwork and hemoviestube spam bots)

    Research Sucuri, 4 Aug 2010

    Recently we started to see a lot of WordPress sites hacked with malware hidden inside the wp_options -siteurlpath table. The symptoms are very similar to the pharma hack (lots of SPAM hidden in the site), but in this case the SPAM is dis...

  8. UFC.com blacklisted by Google (indirectly)

    Research Sucuri, 1 Aug 2010

    Anyone trying to visit the site UFC.com (from Google Chrome or Firefox) will get a big scary warning from Google: Warning: Visiting this site may harm your computer! The website at www.ufc.com contains elements from the site bin.clearspr...

  9. Yet another series of attacks - This time using whereisdudescars.com

    Research Sucuri, 17 Jul 2010

    Update 1: It seems that this attack is limited to only Bluehost and Dreamhost, not GoDaddy like in the previous times. Update 2: This script should fix/clean an infected site: site fix.php Update 3: Attackers are using nowisisdudescars.c...

  10. Fox News Website Hacked

    Research Sucuri, 15 Jul 2010

    We reported yesterday evening that various sites in the Fox web network have been infected with the Pharma Hack. It doesn’t stop there. I just ran some scans on the official Fox News site (foxnews.com) and here are the results: There are...

  11. Various Fox Websites Hit With Pharma Hack

    Research Sucuri, 14 Jul 2010

    If you’ve been following Sucuri, you’ve seen a bunch of discussion around the steadily growing Pharma Hack. As we continue research on the issue we find more and more variations of the exploit. Earlier this evening, we started noticing v...

  12. Understanding and Cleaning the Pharma Hack on WordPress

    Research Sucuri, 13 Jul 2010

    This post is very specific to one type of infection, there are many different types of infections and symptoms, do not be discouraged if the scenario does not fit your situation. There are more recent posts on what pharma hacks look like...

  13. Nagios Community Site Hacked

    Research Sucuri, 13 Jul 2010

    We just detected (via our scanner) that the Nagios community site (community.nagios.org) has been hacked and is redirecting to a Viagra site. The results vary depending on the page request. If you try to visit any page and add a “order=X...

  14. Israel’s permanent mission in the UN web site hacked

    Research Sucuri, 9 Jul 2010

    As we dig into this blackhat SEO spam network, we are finding more and more sites hacked by them. One of the sites we discovered is the http://israel-un.mfa.gov.il (Israeli permanent mission in the UN). It is probable they’ve been exploi...

  15. Argentinean Government web sites hacked with spam

    Research Sucuri, 8 Jul 2010

    We recently blogged that many sites from the Brazilian government got hacked and were being used as part of a large blackhat SEO spam network. Well, the Brazilians are not alone and many web sites from the Argentinean government got hack...

  16. osCommerce users, update your installations as soon as possible

    Research Sucuri, 5 Jul 2010

    If you are an osCommerce user, please make sure to update your installation (and check your sites) as soon as possible. We have been tracking multiple compromises of osCommerce installations where the attackers added this javascript malw...

  17. Bluehost Talks Down Malware Percentages - Offers Sucuri a Forum Ban

    Research Sucuri, 29 Jun 2010

    On Sunday we reported that a number of sites hosted by Bluehost had been hacked (including their CEO’s blog). On Monday while browsing through some of their forums, we noticed a thread regarding the exploit with remarks from forum modera...

  18. Bluehost CEO blog & others exploited by domainameat.cc

    Research Sucuri, 27 Jun 2010

    We’re seeing that a good number of sites hosted at Bluehost have been hacked and infected with malware from domainameat.cc. The blog of Matt Heaton, CEO of Bluehost was also exploited (mattheaton.com). After analyzing some of these sites...

  19. Brazilian Government Websites Hacked with Spam

    Research Sucuri, 23 Jun 2010

    In the last few months we’ve been tracking a common technique being used by attackers: They hack a web site and use that as part of their link farm to build page rank for them on search engines. We posted many articles about similar spam...

  20. Web sites hacked with malware from iopap.upperdarby26.com

    Research Sucuri, 22 Jun 2010

    We are seeing today a good number of sites hacked with malware from http://iopap.upperdarby26.com. The malicious javascript is added to the bottom of every index.php file and to the bottom of a few javascript files as well. The malware i...

  21. Cleaning SPAM from your WordPress blog.

    Research Sucuri, 22 Jun 2010

    A common trend lately is SPAM getting added to WordPress blogs. Attackers are using this to increase their page rank on search engines like Google, Yahoo, etc. So, if you search for your site on Google do you see a bunch of “viagra” cont...

  22. Attack of WordPress blogs on Rackspace

    Research Sucuri, 15 Jun 2010

    Update: It is not a “mass” attack as we described. Sorry about that. A good number of sites were affected (we don’t have a clear number yet), but nothing massive or crazy as our post sounded. If you follow our blog, you probably noticed ...

  23. Mass infection of IIS/ASP sites - 2677.in/yahoo.js

    Research Sucuri, 11 Jun 2010

    A large number of sites have been hacked again in the last few hours with a malware script pointing to https://2677.in/yahoo.js . Not only small sites, but some big ones got hit as well. It is the same SQL injection attack as used in the...

  24. Mass infection of IIS/ASP sites - robint.us

    Research Sucuri, 8 Jun 2010

    An incredibly large number of sites have been hacked in the last day with a malware script pointing to https://ww.robint.us/u.js. Not only small sites, but some big ones got hit as well: https://www.intljobs.org (still hacked) https://ww...

  25. UFSC.br - Brazilian University hosting SEO SPAM

    Research Sucuri, 8 Jun 2010

    UFSC.br (Brazilian Federal university in Santa Catarina), one of the biggest universities in Brazil, is hosting SEO SPAM on almost all their departamental web sites: http://www.sead.ufsc.br - Department for distant education http://cco.i...

  26. Blacklisted sites at Netsol

    Research Sucuri, 3 Jun 2010

    In the last few days many sites hosted at Network Solution got blacklisted by Google. In all of them the report from Google was: URL: sitename Last checked: June 2, 2010 General problem When Google last tested this page, no content was r...

  27. Web site security - It starts with your desktop

    Research Sucuri, 2 Jun 2010

    If you have a web site and you want it to be secure, the first place you have protect is your desktop. Recently (well, since 2009), a large number of sites have been infected with malware and blacklisted due to a few desktop virus (gener...

  28. WordPress user: Be careful where you get your theme from

    Research Sucuri, 1 Jun 2010

    WordPress themes are not just design templates, they contain PHP code and must be validated before use. Not only because of bugs, but some may contain malicious code in there. Specially if you download from random web sites and not from ...

  29. Google top 1000 sites: Interesting stats about them

    Research Sucuri, 1 Jun 2010

    Google recently published a list with the top 1000 most visited web sites in the world. We found that list very interesting and decided to take a closer look at them. These are stats we took: Web servers in use Programming language in us...

  30. SEO SPAM network - Code used and more details

    Research Sucuri, 27 May 2010

    Lately we have been talking a lot about WordPress sites getting hacked with SEO Spam: 1-SEO SPAM network - Details of the wp-includes infection 2-It is not over - SEO Spam on sites infected Some big sites got infected and the common comp...

  31. SEO SPAM network - Details of the wp-includes infection

    Research Sucuri, 25 May 2010

    We have been digging lately in a large SEO SPAM network which is using thousands of compromised sites to increase their page rankings and spread malware. They are similar to the one we reported earlier affecting lean.mit.edu, but this ti...

  32. All the sites at the Walmart Community network hacked

    Research Sucuri, 20 May 2010

    We posted a few weeks ago that the main site for the Walmart community network was hacked. Well, the problem is a lot bigger than that. They have web sites for different cities and most of them are hacked too. For example: http://arkansa...

  33. Lean.mit.edu hacked and serving spam

    Research Sucuri, 17 May 2010

    Interested in Viagra, Cialis and some other “magical” medications? It seems that the MIT web site for the Lean Advancement Initiative (https://lean.mit.edu/ ) knows a bit about it: Joking aside, they got hacked and are being used to serv...

  34. It is not over - SEO Spam on sites infected

    Research Sucuri, 13 May 2010

    Did your site got hacked on the last 3 or 4 weeks? If it did, you may still have some things to clean up. We lately started to notice in a lot of sites that we have been fixing a “.files” directory full of spam links on them. We initiall...

  35. Lots of sites reinfected - Now using holasionweb.com

    Research Sucuri, 12 May 2010

    Update2: Reply from GoDaddy: https://blog.sucuri.net/2010/05/reply-from-godaddy-regarding-latest.html Update: Code used to exploit found: https://blog.sucuri.net/2010/05/found-code-used-to-inject-malware-at.html We just got reports this ...

  36. Last week attacks - Some comments and updates

    Research Sucuri, 11 May 2010

    Last week as a busy one. First, thousands of GoDaddy sites got hacked with that kdjkfjskdfjlskdjf.com malware. A few days later, hundreds of Network Solutions sites got hacked by using the php.ini/cgi-bin malware (including the US Treasu...

  37. Serendipity important security update

    Research Sucuri, 11 May 2010

    If you are using Serendipity, stop everything you are doing and read this: Serendipity 1.5.3 has been released, as a security-fix release with no other relevant changes. A security issue has been discovered by Stefan Esser during the cou...

  38. Simple cleanup solution for the latest WordPress hack

    Research Sucuri, 8 May 2010

    Updated 20160914 This post is very specific to one type of infection, there are many different types of infections and symptoms, do not be discouraged if the scenario does not fit your situation. A more detailed guide on how to address a...

  39. New attack today against WordPress

    Research Sucuri, 7 May 2010

    Update 2: Simple clean up solution: https://blog.sucuri.net/2010/05/simple-cleanup-solution-for-latest.html Update 1: Note that we are not blaming WordPress here. I am assuming that if the problem was on WordPress itself, the number of i...

  40. New infections today at Network Solutions

    Research Sucuri, 4 May 2010

    Update: We just heard back from Network solutions and they explained the issue to us. It is also related to the US Treasury Department hack, because they are hosting at Netsol and got infected too. On their own words: “ This past weekend...

  41. Walmart community web site still hacked

    Research Sucuri, 30 Apr 2010

    Remember a few weeks ago when we reported that the official web site for the Walmart Community Action Network was hacked and hosting SEO spam? Well, it seems that they removed the previous spam and also upgraded WordPress to latest versi...

  42. SunTrust phishing - case study

    Research Sucuri, 28 Apr 2010

    Last week we were called to fix a Joomla site that got blacklisted and had some malware on it. Nothing unusual as we do that many times a day. However, after some analysis of the site, we found a directory that didn’t look quite right. T...

  43. A new place to hide web-based malware: php.ini + cgi-bin

    Research Sucuri, 26 Apr 2010

    We got a call this weekend from a desperate site owner that had just found out that his site was hacked and hosting malware. He was fairly technical and checked everywhere for it. He even reverted back to an old backup he knew was clean,...

  44. Network Solutions update and some numbers

    Research Sucuri, 24 Apr 2010

    I am getting a lot of questions via email or via the comments on what to do if a site hosted at Network Solutions is currently with malware or blacklisted. Network Solutions issued an update explaining what to do: http://blog.networksolu...

  45. Improper separation of hosting accounts is putting customers at risk

    Research Sucuri, 18 Apr 2010

    If you are hosting your site at Hostek.com, you are currently at a higher risk of being hacked. Why? Because they do not currently perform proper separation of accounts internally, so anyone can access the pages of everyone else. How do ...

  46. Network Solutions hacked again

    Research Sucuri, 18 Apr 2010

    Network Solutions is getting hacked again. Just today we were notified of more than 50 sites hacked with the following malware javascript: If we decode this javascript, we see that it is injecting this iframe from http://corpadsinc.com/g...

  47. Walmart web site hacked and hosting spam

    Research Sucuri, 15 Apr 2010

    A few days ago someone contacted us asking for help to clean up their site. They got hacked and the attacker added a bunch of spam links to it. We fixed it for them and we decided to search for more sites that were also infected. Our sur...

  48. Conditional redirects (or the htaccess malware)

    Research Sucuri, 13 Apr 2010

    We see all types of malware daily, but one of them seems to cause a lot of confusion to our users (and everyone in general). This is the common question we hear: “Some users are complaining that when they search for my site on Google, th...

  49. Details on the Network Solutions / WordPress mass hack

    Research Sucuri, 10 Apr 2010

    Update 1: The attack continues! Now they are using the domain http://mainnetsoll.com/grep/. Make sure to fix your wp-config and change your database password ASAP. Update 2: A quick fix if you can’t change your database password. Set the...

  50. Mass infection of WordPress blogs at Network Solutions

    Research Sucuri, 9 Apr 2010

    Since yesterday we are seeing a large number of WordPress blogs (running the latest version 2.9.2) getting infected with malware. None of them are using the same plugins or the same themes. Some of them even have wp-admin access blocked ...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support