Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,878 reports kept since 2009. Updated automatically every 10 minutes. Last checked 5 min ago.

  1. Patchstack: The Highest-Quality WordPress Vulnerability Data

    Research Patchstack, 30 Apr 2025

    Patchstack has been the leading WordPress threat intelligence provider for many years. This success results from high-quality security research, pioneering efforts in WordPress bug bounty hunting, and fostering strong collaboration betwe...

  2. The 7 Best WordPress Event Plugins (Ranked by Quality & Security)

    Research Patchstack, 30 Apr 2025

    Managing events on your WordPress site can be challenging. Whether you’re hosting workshops, webinars, conferences, or community meetups, keeping everything organized requires the right tools. With so many WordPress event plugins availab...

  3. The 6 Best WordPress Calendar Plugins (Ranked by Quality & Security)

    Research Patchstack, 29 Apr 2025

    Still juggling spreadsheets and emails to manage events on your WordPress website? Struggling to find a scheduling tool that actually works for your specific needs? Managing events on your WordPress site shouldn’t be a headache. The righ...

  4. The 5 Best WordPress Newsletter Plugins (Ranked by Quality & Security)

    Research Patchstack, 28 Apr 2025

    Email remains one of the most direct and effective ways to connect with your audience. But if you’re running a WordPress site, the real challenge is choosing a plugin that fits your goals - without adding unnecessary complexity. That’s w...

  5. Fake GIF Leveraged in Multi-Stage Reverse-Proxy Card Skimming Attack

    Research Sucuri, 25 Apr 2025

    In today’s post we’re going to review a sophisticated, multi-stage carding attack on a Magento eCommerce website. This malware leveraged a fake gif image file, local browser sessionStorage data, and tampered with the website traffic usin...

  6. Fake Security Vulnerability Phishing Campaign Targets WooCommerce Users

    Research Patchstack, 23 Apr 2025

    The Patchstack team has been monitoring a large-scale phishing campaign using a sophisticated email and web-based phishing template to warn users of a supposed security vulnerability in their WooCommerce installation. This attack bears a...

  7. A Hacker’s Perspective on WordPress Security - Q&A with Mat Rollings (Stealthcopter)

    Research Patchstack, 18 Apr 2025

    “There’s no shame in having a vulnerability; the shame might be in how you handle it.” WordPress security often gets questioned, but many of those questions are directed at plugin developers. We sat down with Mat Rollings, aka Stealthcop...

  8. When Good Software Goes Bad

    Research Sucuri, 18 Apr 2025

    Most often bad actors try their best to hide their activities by using obfuscated code or by uploading fake plugins or themes that inject simple but malicious scripts into a site. Every now and then we encounter a case where legitimate s...

  9. Critical RomethemeKit For Elementor Plugin Vulnerability Patched

    Research Patchstack, 17 Apr 2025

    This blog post is about the RomethemeKit For Elementor plugin vulnerability. If you’re a RomethemeKit For Elementor user, please update the plugin to at least version 1.5.5. About the RomethemeKit For Elementor plugin The plugin Romethem...

  10. Ad-Jacked: Cybercriminals Inject Google Adsense into WordPress

    Research Sucuri, 15 Apr 2025

    Recently, we’ve encountered cases where WordPress websites were impacted by Google Adsense hijackers. Attackers inject advertisements and scripts that steal website resources and pump ad views for their adsense accounts. This is not the ...

  11. The 7 Best WordPress Table Plugins (Ranked by Quality & Security)

    Research Patchstack, 12 Apr 2025

    Are you tired of wrestling with HTML or struggling to display data clearly on your site? A WordPress table plugin can transform how you present information, making everything from pricing comparisons to complex datasets look professional...

  12. The 6 Best WordPress Popup Plugins Compared (Ranked by Quality & Security)

    Research Patchstack, 11 Apr 2025

    Tired of watching website visitors leave without converting? Imagine instantly boosting your email list, promoting irresistible offers, and seamlessly guiding users through your site - all with a few strategically placed popups. Creating...

  13. Fake Font Domain Used to Skim Credit Card Data

    Research Sucuri, 10 Apr 2025

    Recently, a client of ours came to us concerned about credit card theft on their WordPress site. The client’s users reported that their credit card data had become compromised shortly after purchasing products on our client’s website. Wh...

  14. Critical SureTriggers Plugin Vulnerability Exploited within 4 hours

    Research Patchstack, 10 Apr 2025

    Vulnerability Information On April 10, 2025, a critical vulnerability in the WordPress plugin SureTriggers (version 1.0.78 and below) was identified and published. This flaw, allows unauthenticated attackers to create administrative user...

  15. The 7 Best WordPress Translation Plugins (Ranked by Quality & Security)

    Research Patchstack, 8 Apr 2025

    Most websites are developed in English, but using a region’s local language can often boost conversion rates. If using WordPress, you can easily do this using WordPress translation plugins. As Patchstack’s security experts, we’ve analyze...

  16. Vulnerability & Patch Roundup - March 2025

    Research Sucuri, 31 Mar 2025

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  17. Hidden Malware Strikes Again: Mu-Plugins Under Attack

    Research Sucuri, 28 Mar 2025

    At Sucuri, our security researchers continually monitor for new malware variants and infection techniques targeting WordPress websites. Recently, we’ve uncovered multiple cases where threat actors are leveraging the mu-plugins directory ...

  18. Cloudfest Hackathon 2025: SBOMinator to Secure the OSS Supply Chain

    Research Patchstack, 27 Mar 2025

    No one can do it alone and that’s nowhere quite as obvious as it is in open-source software. With different dependencies and whole ecosystems needing to work in perfect sync in order to stay secure, protecting supply chains is vital. In ...

  19. How to Detect and Prevent Unauthorized Access in WordPress

    Research Patchstack, 27 Mar 2025

    This article was originally authored by Robert Abela of Melapress, a Patchstack partner specializing in WordPress security and user management solutions. Unauthorized WordPress access is more common than you might think. Learning how to ...

  20. New Year, New Threats: Q1 2025’s Most Exploited WordPress Vulnerabilities

    Research Patchstack, 27 Mar 2025

    WordPress, powering over 40% of websites, is a prime target for cyberattacks. Virtual patches (vPatches) provide immediate protection against vulnerabilities in plugins and themes, ensuring site security while awaiting official fixes.

  21. Critical LFI to RCE Vulnerability in WP Ghost Plugin Affecting 200k+ Sites

    Research Patchstack, 20 Mar 2025

    This blog post is about the WP Ghost plugin vulnerability. If you’re a WP Ghost user, please update the plugin to at least version 5.4.02. About the WP Ghost plugin The plugin WP Ghost, which has over 200k active installations, is one of...

  22. Fake Cloudflare Verification Results in LummaStealer Trojan Infections

    Research Sucuri, 19 Mar 2025

    Today’s blog post will be a follow up to a previous article we posted a few weeks ago: We continue to see new variants of this malware campaign emerge. WordPress websites continue to be used as staging grounds to trick website visitors i...

  23. Credit Card Skimmer and Backdoor on WordPress E-commerce Site

    Research Sucuri, 14 Mar 2025

    The battle against e-commerce malware continues to intensify, with attackers deploying increasingly sophisticated tactics. In a recent case at Sucuri, a customer reported suspicious files and unexpected behavior on their WordPress site. ...

  24. Cascading Redirects: Unmasking a Multi-Site JavaScript Malware Campaign

    Research Sucuri, 6 Mar 2025

    During a recent website security investigation, we uncovered a malicious JavaScript injection affecting a WordPress website. The infection was responsible for redirecting visitors to unwanted third-party domains, ultimately harming the s...

  25. Unauthenticated Arbitrary File Upload Vulnerability in Chaty Pro Plugin

    Research Patchstack, 5 Mar 2025

    This blog post discusses about the findings on the Chaty Pro plugin. This vulnerability is fixed on version 3.3.4 and the vulnerable function didn’t exist on free version (Chaty) of the plugin. About the Chaty Pro Plugin The Chaty Pro pl...

  26. Vulnerability & Patch Roundup - February 2025

    Research Sucuri, 1 Mar 2025

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  27. Fake WordPress Plugin Impacts SEO by Injecting Casino Spam

    Research Sucuri, 26 Feb 2025

    Injecting malware via a fake WordPress plugin has been a common tactic of attackers for some time. This clever method is often used to bypass detection as attackers exploit the fact that plugins are not part of the core files of a WordPr...

  28. The Best WooCommerce Security Plugins

    Research Patchstack, 26 Feb 2025

    Is your WooCommerce store truly secure? If you cannot confidently say “Yes!” then it is vital to be aware that just one single security breach could easily cripple your business overnight. This can quickly lead to financial losses, reput...

  29. Reflected XSS Patched in Essential Addons for Elementor Affecting 2+ Million Sites

    Research Patchstack, 24 Feb 2025

    This blog post is about the Essential Addons for Elementor plugin vulnerability. If you’re an Essential Addons for Elementor user, please update the plugin to at least version 6.0.15. About the Essential Addons for Elementor plugin The p...

  30. WordPress ClickFix Malware Causes Google Warnings and Infected Computers

    Research Sucuri, 21 Feb 2025

    Since December of last year there has been a new fake Google reCAPTCHA campaign making its way through the WordPress world. Very similar to malware which we wrote about last Summer, the website malware injection attempts to trick unsuspe...

  31. Critical Privilege Escalation Patched in KLEO Theme’s Plugin

    Research Patchstack, 20 Feb 2025

    This blog post is about the K Elements plugin vulnerability. If you’re a KLEO theme user who is using the K Elements plugin, please update the plugin to at least version 5.4.0. About the KLEO Theme The theme KLEO which has over 23,000 sa...

  32. Hidden Backdoors Uncovered in WordPress Malware Investigation

    Research Sucuri, 14 Feb 2025

    At Sucuri, we often encounter cases where malware is deeply embedded in websites, hidden in files and scripts that can easily escape detection. In this article, we’ll walk you through a real-life incident where a customer contacted us ab...

  33. Magento Credit Card Stealer Disguised in an <img> Tag

    Research Sucuri, 12 Feb 2025

    Tag" align="center" style="display: block;margin: 0 auto 20px;max-width:100%" /> Recently, we had a client come to us concerned that their website was infected with credit card stealing malware, often referred to as MageCart. Their websi...

  34. Google Tag Manager Skimmer Steals Credit Card Info From Magento Site

    Research Sucuri, 6 Feb 2025

    At Sucuri, we are committed to protecting websites from malware and other cyber threats. Recently, we were contacted by a customer who had experienced credit card data theft from their Magento-based eCommerce website. After an extensive ...

  35. Rare Case of Privilege Escalation in ASE Plugin Affecting 100k+ Sites

    Research Patchstack, 5 Feb 2025

    This blog post is about the Admin and Site Enhancements (ASE) free and pro plugin vulnerability. If you’re an Admin and Site Enhancements (ASE) user, please update the plugin to at least version 7.6.3. About the Admin and Site Enhancemen...

  36. Vulnerability & Patch Roundup - January 2025

    Research Sucuri, 31 Jan 2025

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  37. Privilege Escalation Vulnerability Patched in Better Find and Replace Plugin

    Research Patchstack, 29 Jan 2025

    This blog post is about the Better Find and Replace plugin vulnerability. If you’re a Better Find and Replace user, please update the plugin to at least version 1.6.8. About the Better Find and Replace Plugin The plugin Better Find and R...

  38. Malware Redirects WordPress Traffic to Harmful Sites

    Research Sucuri, 24 Jan 2025

    Recently, a customer approached us after noticing their website was redirecting visitors to a suspicious URL. They suspected their site had been compromised and sought assistance in identifying and resolving the issue. This prompted a de...

  39. Unauthenticated Privilege Escalation Vulnerability in RH - Real Estate Theme

    Research Patchstack, 22 Jan 2025

    This blog post discusses about the findings on the RealHome theme and the plugin that is installed with it Easy Real Estate. Currently there are no known updates to fix this issue so if you are a user of the theme and plugin disabling th...

  40. Backdoors: The Hidden Threat Lurking in Your Website

    Research Sucuri, 17 Jan 2025

    Website backdoors are a silent yet deadly threat to website security. These stealthy mechanisms bypass standard authentication, providing attackers with persistent, unauthorized access to a website’s backend. Often overlooked, backdoors ...

  41. Japanese Spam on a Cleaned WordPress Site: The Hidden Sitemap Problem

    Research Sucuri, 15 Jan 2025

    While investigating a compromised WordPress site, we discovered a malware infection causing Japanese spam links to appear in Google search results. Although the site had been cleaned, Google was still crawling and indexing spammy URLs, w...

  42. How & Why You Should Remove Unused WordPress Plugins

    Research Patchstack, 14 Jan 2025

    As a seasoned WordPress developer, you might have spent countless hours perfecting your WordPress site by carefully selecting themes and plugins to create an outstanding experience. But did you stop and think about all the plugins that y...

  43. Critical Vulnerability Patched in GiveWP Plugin

    Research Patchstack, 10 Jan 2025

    The vulnerability in the GiveWP plugin was originally reported by Patchstack Alliance community member Edisc from Zalopay Security to the Patchstack Zero Day bug bounty program for WordPress. Patchstack Zero Day program has awarded the r...

  44. Stealthy Credit Card Skimmer Targets WordPress Checkout Pages via Database Injection

    Research Sucuri, 9 Jan 2025

    Recently, we released an article where a credit card skimmer was targeting checkout pages on a Magento site. Now we’ve come across sophisticated credit card skimmer malware while investigating a compromised WordPress website. This credit...

  45. Critical Vulnerabilities Found in Fancy Product Designer Plugin

    Research Patchstack, 8 Jan 2025

    This blog post is about Fancy Product Designer plugin vulnerabilities. If you’re a Fancy Product Designer user, please delete or deactivate the plugin until the patch is released by the vendor. About the Fancy Product Designer Plugin The...

  46. Vulnerability & Patch Roundup - December 2024

    Research Sucuri, 7 Jan 2025

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  47. Hardening WordPress - A Checklist To Get Started

    Research Patchstack, 27 Dec 2024

    These days, spinning up a new WordPress website is quick and easy, but securing it is not so straightforward. In this post, we will cover some of the most critical things that you need to consider when setting up security for your WordPr...

  48. How to Fix the WordPress Redirect Hack

    Research Patchstack, 24 Dec 2024

    As a WordPress site owner, dealing with the aftermath of a redirect hack can be a daunting and frustrating experience. Malicious actors are constantly finding new ways to exploit vulnerabilities and hijack your website, redirecting your ...

  49. SQL Injection in WordPress - Everything You Need To Know

    Research Patchstack, 23 Dec 2024

    If you manage a WordPress website, you may have heard of SQL injection (also known as SQLi), a type of cyberattack. If so, you’ll probably know how ludicrously simple they are - and how devastating. Whether you’re familiar with this type...

  50. Multiple Critical Vulnerabilities Patched in WPLMS and VibeBP Plugins

    Research Patchstack, 23 Dec 2024

    This blog post is about the WPLMS and VibeBP vulnerabilities. If you’re a WPLMS and VibeBP user, please update the plugin to at least version 1.9.9.5.3 and 1.9.9.7.7 respectively. About the WPLMS and VibeBP Plugins Both of the plugins ar...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support