Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,880 reports kept since 2009. Updated automatically every 10 minutes. Last checked 36 min ago.

  1. Brazilian government site hacked

    Research Sucuri, 8 Apr 2010

    Today our honeypot detected one more .gov site hacked (among the thousands we see daily). This time from the Brazilian government. The site in question is http://www.sefaz.mt.gov.br. We started to see RFI requests trying to use a file pl...

  2. Malware hiding from Google

    Research Sucuri, 7 Apr 2010

    Google is getting pretty good at detecting web-based malware and blacklisting the sites that are hosting it. This means bad business for the attackers (or “hackers”, as the media like the call them) and as a result they are already chang...

  3. Ghana Judicial Service site hacked

    Research Sucuri, 6 Apr 2010

    Yesterday we started to see RFI attacks against our honeypots using files hosted from http://www.judicial.gov.gh (Ghana’s official Judicial Service site). These are some of the entries we are seeing: a.18.218.14 - - [05/Apr/2010:11:22:26...

  4. Targeted web-based malware - Case study

    Research Sucuri, 5 Apr 2010

    We deal with web-based malware every day here at Sucuri. Most of them are very simple and easy to detect, but once in a while we face some that are very complex and targeted. This case study is about the later, a targeted attack against ...

  5. ForTransRis hosting malware and attacking our honeypots

    Research Sucuri, 5 Apr 2010

    ForTransRIS Project is a Coordination Action funded by the European Commission under the OMC-NET (Open Method of Coordination-NET) strategy of the Sixth Framework Programme for Research and Technological Development, managed by the DG Re...

  6. Kernel.org funny April fools joke

    Research Sucuri, 1 Apr 2010

    We have been monitoring kernel.org (and many other open source projects sites) with our web integrity monitoring solution and I was surprised to see a big change on their site today. It looked like some message in Russian was added and I...

  7. Lots of Italian sites getting hacked - Initial analysis

    Research Sucuri, 31 Mar 2010

    On the last few days we are seeing a large number of reports from Italian sites getting hacked. Way more than the average and way more than from any other country. We got a chance to analyze a couple of them and they all look very much t...

  8. APT - Attempting to steal your domain

    Research Sucuri, 31 Mar 2010

    We all hear of APT (advanced persistent threat) and this is a good example of one trying to steal the vl.com domain. Very good read: Dreamhost account hacked Continue reading APT - Attempting to steal your domain at Sucuri Blog.

  9. Perl.com hacked - Security archive case study

    Research Sucuri, 24 Mar 2010

    Security Archive: Remembering security incidents to make sure we don’t commit the same mistakes over and over again. Want to read more stories like this one? Follow @sucuri_security on twitter or subscribe to our RSS feed. Interested in ...

  10. Today is not a good day to be blacklisted

    Research Sucuri, 17 Mar 2010

    Today is definitely not a good day to be blacklisted as Google seems to be “busy”. We have been trying to help some clients to get their sites reviewed and removed from Google’s blacklist, but all we get at the “Webmasters tools” is: “Ou...

  11. Removing malware from a web site - Case Study

    Research Sucuri, 16 Mar 2010

    We deal with web-based malware every day here at Sucuri. Some are encrypted and very hard to detect and remove, but most of them are not. This case study is about the later, simpler, but very annoying web-based javascript malware that we...

  12. Ecuador Government site hacked and spreading malware

    Research Sucuri, 8 Mar 2010

    Colombia, Venezuela and now Ecuador. How far are we from reporting the whole South America? 🙂 The web site from the ‘Municipio del Cantón Mejía’ in Ecuador has been hosting malware and also attacking our honeypots for a while. As always...

  13. Venezuela Government site hacked and spreading malware

    Research Sucuri, 3 Mar 2010

    Since we have been noticing that full-disclosure works, we will continue with that. We have detected in our honeypots that since January the site www.miranda.gov.ve (from the Venezuela state of Miranda) has been hosting malware and their...

  14. Honeypot analysis - Full disclosure works

    Research Sucuri, 1 Mar 2010

    When all else fails, *full disclosure (the process) seems to work. Early in January, we sent a bunch of emails to the people at the Georgia Government, after we detected that they were hosting malware. We asked for contacts on Twitter. N...

  15. Colombia Government sites hacked (and spreading malware)

    Research Sucuri, 18 Feb 2010

    You would expect that a security-related web site would be secure, no? What about an official web site from a Government? Should that be safe? What about a government web site about security? Shouldn’t that be ultra super secure? (yes, I...

  16. Georgia government sites hacked (and spreading malware)

    Research Sucuri, 15 Feb 2010

    *UPDATE: A few hours after this post, they removed the malware from justice.gov.ge and other sites. I am glad we had some effect. You know, you would think that after all the attacks that Georgia suffered in 2008 they would be more caref...

  17. Removing Malware From a WordPress Blog - Case Study

    Research Sucuri, 12 Feb 2010

    This post is very specific to one type of infection. There are many different types of WordPress infections and symptoms, do not be discouraged if the scenario does not fit your situation. You can also follow the instructions in our new ...

  18. Fingerprinting web applications

    Research Sucuri, 29 Jan 2010

    This paper describes a technique to remotely detect the version (fingerprint) of a web application. We cover WordPress, Mediawiki and Joomla in the article, but it can be easily extended to other applications. At the end, we also give yo...

  19. apache.org hacked?

    Research Sucuri, 28 Aug 2009

    Apache.org was down for a while this morning and shortly after they released a note about a compromise: This is a short overview of what happened on Friday August 28 2009 to the apache.org services. A more detailed post will come at a la...

  20. servage.net mass defaced again

    Research Sucuri, 18 Aug 2009

    It seems that http://www.servage.net/ has been mass defaced again. It is not the first time I hear about them, but it seems they get hacked way too often. My suggestion: Host your pages on private/dedicated servers (some are as cheap as ...

  21. WordPress

    Research Sucuri, 11 Aug 2009

    How to annoy a wordpress admin? By changing his password without confirmation… WordPress get_row($wpdb-prepare(“SELECT * FROM $wpdb-users WHERE user_activation_key = %s”, $key)); if ( empty( $user ) ) return new WP_Error(‘invalid_key’, _...

  22. Twitter is down, productivity is up

    Research Sucuri, 6 Aug 2009

    Twitter has been down for more than one hour today and I suddenly noticed an increased productivity from my peers… any correlation? Maybe that’s related to the latest “worm”, where thousands of users were posting “Today was so exciting! ...

  23. Multiple top-security sites hacked (zf05)

    Research Sucuri, 29 Jul 2009

    If you follow the full disclosure mailing list, you are probably aware that many sites of top security professionals were hacked (including Kevin Mitnick, Robert Lemos from Security Focus, Dan Kaminsky, etc). I know how easy it is to for...

  24. Matasano.com hacked

    Research Sucuri, 25 Jul 2009

    Matasano has just been hacked. They are one of the top security web sites with an amazing group of professionals. This is the screenshot: I don’t know what happened, but it probably wasn’t a 0-day as people are saying. If anti-sec really...

  25. Sonia Gandhi site hacked

    Research Sucuri, 23 Jul 2009

    It is not the first time her site got hacked, but we would image that they would be taking their security a bit better by now. Not only her, but the site of Manmohan Singh (Indian Prime Minister) got hacked too.. And everyone on Twitter ...

  26. Australian Air Force site hacked

    Research Sucuri, 13 Jul 2009

    And it it still defaced (for more than couple of hours). Link http://www.airforce.gov.au/. Snapshot: Continue reading Australian Air Force site hacked at Sucuri Blog.

  27. Blog Security Stats - Taking almost 2k blogs to a security test

    Research Sucuri, 11 Jun 2009

    The goal of this research is to determine if bloggers are taking the security of their sites seriously. We focused on self-hosted WordPress blogs, since the ones from blogger, WordPress.com and others handle the security transparently fo...

  28. Hackers hit U.S. Army websites

    Research Sucuri, 2 Jun 2009

    “A group of computer hackers based in Turkey breached the sites of two U.S. Army facilities, leveraging SQL injection attacks, according to reports.The group, which calls itself “m0sted,” defaced the page and redirected users to pages th...

  29. Security benefits of Network-based Integrity Monitoring

    Research Sucuri, 20 May 2009

    Network-based integrity monitoring offers additional protection that you don’t get by anti-viruses or traditional intrusion detection tools. Sucuri NBIM will monitor your internet presence, looking for changes that might have been caused...

  30. WordPress Hardening

    Research Sucuri, 8 May 2009

    This document is not the common step-by-step guide on how to protect your wordpress installation. A lot of sites cover that already, so I will talk about some additional topics that you don’t see around very often, specially torwards sec...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support