HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,878 reports kept since 2009. Updated automatically every 10 minutes. Last checked 8 min ago.
- How to Configure the X-Frame-Options Header in WordPress
Research Patchstack, 22 Dec 2024
When you visit any website on the internet, the server delivering the web page instructs your browser on how to process this information by passing meta-data called headers. In this post, we’ll explore the importance of the X-Frame-Optio...
- How To Protect WordPress Against Cross-Site Scripting Attacks (XSS)
Research Patchstack, 22 Dec 2024
Cross-site scripting (XSS) is an exploitation technique that allows hackers to run arbitrary code on a compromised website. Needless to say, it is a serious risk for any web application, and our experts at Patchstack regularly receive no...
- Understanding Cookie Stealing Attacks: How They Work and Their Impact on WordPress Users
Research Patchstack, 21 Dec 2024
If you stay up to date with cyber security news, you might have heard of Google’s Threat Analysis Group discovering a financially motivated phishing campaign targeting YouTubers. Researchers found that attackers lured creators with fake ...
- Vulnerability & Patch Roundup - November 2024
Research Sucuri, 20 Dec 2024
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- What to do if your WooCommerce site gets hacked: A 10-step recovery process
Research Patchstack, 17 Dec 2024
Did worse come to worst and you strongly suspect your WooCommerce store got hacked? We’ll check, going through the key signs, then fight the fire to get you back online (safely) ASAP and show you how to emerge stronger. Let’s get this so...
- Virtual Patches vs. Hackers: Q4 2024’s Most Exploited WordPress Threats
Research Patchstack, 17 Dec 2024
WordPress, powering over 40% of websites, is a prime target for cyberattacks. Virtual patches (vPatches) provide immediate protection against vulnerabilities in plugins and themes, ensuring site security while awaiting official fixes.
- Multiple Critical Vulnerabilities Patched in Woffice Theme
Research Patchstack, 12 Dec 2024
This blog post is about the Woffice theme vulnerabilities. If you’re a Woffice user, please update the theme to at least version 5.4.15. About the Woffice Theme The theme Woffice, which has over 15,000 sales, is a popular premium intrane...
- Unauthorized Plugin Installation/Activation in Hunk Companion
Research WPScan, 10 Dec 2024
This report highlights a vulnerability in the Hunk Companion plugin < 1.9.0 that allows unauthenticated POST requests to install and activate plugins directly from the WordPress.org repository. This flaw poses a significant security risk...
- Malicious Script Injection on WordPress Sites
Research Sucuri, 5 Dec 2024
Recently, our team discovered a JavaScript-based malware affecting WordPress sites, primarily targeting those using the Hello Elementor theme. This type of malware is commonly embedded within legitimate-looking website files to load scri...
- Unauthenticated Privilege Escalation Vulnerability Patched in Sweet Date Theme
Research Patchstack, 5 Dec 2024
This blog post discusses about the findings on the Sweet Date theme. If you’re a Sweet Date user, please update the theme to version 3.8.0 or higher. About the Sweet Date Theme The Sweet Date theme (premium version), which has nearly 10,...
- The Last WordPress Security Checklist You’ll Ever Read
Research Patchstack, 1 Dec 2024
Is your WordPress site secure? You might think so, but are you prepared for the unexpected? The whitehat researchers at Patchstack found that most WordPress vulnerabilities arise not from the core platform but from overlooked weaknesses ...
- Authenticated RCE Patched in Rank Math SEO plugin
Research Patchstack, 28 Nov 2024
This blog post is about an arbitrary .htaccess file overwrite vulnerability on the Rank Matho SEO plugin. If you’re a Rank Math SEO plugin user, please update the plugin to the latest version or at least to the version 1.0.232. About Ran...
- Credit Card Skimmer Malware Targeting Magento Checkout Pages
Research Sucuri, 27 Nov 2024
Magento websites are a frequent target for cybercriminals due to their widespread usage in eCommerce and the valuable customer data they handle. During a routine investigation, we discovered a malicious JavaScript injection targeting Mag...
- Unauthenticated Arbitrary File Read Vulnerability in Jobify Theme
Research Patchstack, 21 Nov 2024
This blog post is about an unauthenticated arbitrary file read vulnerability on the Jobify theme. If you’re a Jobify user, please delete or deactivate the theme until the patch is released by the vendor. About Jobify theme The theme Jobi...
- The 5 Best WordPress Image Optimization Plugins (Tests Included)
Research Patchstack, 20 Nov 2024
Is your website slow? It might be due to high-resolution images. While adding more images to your website makes it more engaging, it also increases its size. This means people with a slow internet connection might experience a sluggish w...
- Handling plugin security: Interview with LiteSpeed Cache’s Hai Zheng
Research Patchstack, 20 Nov 2024
Today we present an interview with Hai Zheng. Hai works at LiteSpeed Technologies and is a man who chases better code and products tirelessly, so before he knew it, he just happened to learn PHP, JS, CSS, React, NodeJS, Python, Go, MySQL...
- Protect Your Store: The Ultimate WooCommerce Security Checklist
Research Patchstack, 15 Nov 2024
When you get hacked, it’s too late to think about security. However, getting started with securing your WooCommerce store (or the stores you create as a developer) isn’t always easy. So in this checklist, I’ll give you actionable pointer...
- Simple Include Statement Hides Casino Spam
Research Sucuri, 14 Nov 2024
Just as there are countless types of websites on the internet, there are just as many attackers seeking to exploit them. These attackers develop malicious code that continuously evolves, constantly finding new ways to harm their next tar...
- Critical Account Takeover Patched in Really Simple Security Plugin
Research Patchstack, 14 Nov 2024
This blog post is about the Realy Simple Security plugin vulnerability. If you’re a Realy Simple Security user, please update the free, pro, and pro multisite plugin to at least version 9.1.2. About the Really Simple Security Plugin The ...
- PHP Reinfector and Backdoor Malware Target WordPress Sites
Research Sucuri, 13 Nov 2024
We recently observed a surge in WordPress websites being infected by a sophisticated PHP reinfector and backdoor malware. While we initially believed that the infection was linked to the wpcode plugin, we found that several sites without...
- Nearly 1000 Plugins Closed During WordPress Security Cleanup
Research Patchstack, 13 Nov 2024
Patchstack is always looking for new ways to make the WordPress ecosystem safer by organizing various events for ethical hackers and security researchers. Our experiments sometimes lead to unexpected results. Also, these events sometimes...
- Malware Steals Account Credentials
Research Sucuri, 8 Nov 2024
It’s common for malware to target e-commerce sites, and these attackers are usually seeking to steal credit card details. In most cases, they will insert scripts that extract data from the checkout forms to siphon fields like the cardhol...
- 2024 Credit Card Theft Season Arrives
Research Sucuri, 7 Nov 2024
The holiday shopping season is just around the corner, and it’s the time of year the eCommerce website owners need to be most on their guard. Credit card stealing malware, commonly referred to as “MageCart”, is most rampant during the ho...
- Identifying Traffic from Shell Finder Bots
Research WPScan, 1 Nov 2024
A shell finder is a type of reconnaissance tool that is used by threat actors to identify websites that have already been compromised and contain backdoor shells. A backdoor shell is a form of malware that is added by a threat actor afte...
- WordPress Vulnerability & Patch Roundup October 2024
Research Sucuri, 1 Nov 2024
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- Rogue Ads Redirect Visitors
Research Sucuri, 31 Oct 2024
Ads are everywhere. They generate revenue for site owners and can present related content to the website being visited. As detailed in previous articles, bad actors often take advantage of that functionality. Quite often rogue ad network...
- Indonesian Gambling Redirect Hiding in Plain Sight
Research Sucuri, 30 Oct 2024
Many pieces of malware found over the years have been complex and difficult to find. Attackers often obfuscate their code to make it harder to track. Some pieces of malware require extensive reviews to uncover. But in other instances, th...
- WordPress Salts: What Are They, How They Work, and How to Use Them
Research Patchstack, 30 Oct 2024
If you have been developing WordPress websites, your eyes might have wandered to the ‘WordPress salts’ section of the wp.config.php file. Have you ever wondered what these salts are and why we need them? If you answered ‘Yes’, then you a...
- Rare Case of Privilege Escalation Patched in LiteSpeed Cache Plugin
Research Patchstack, 29 Oct 2024
The vulnerability in the LiteSpeed Cache plugin was originally reported by Patchstack Alliance community member TaiYou to the Patchstack bug bounty program for WordPress. We are collaborating with the researcher to release the content of...
- Fake “Fix It” Pop-Ups Target WordPress Sites via Malicious Plugin to Download Trojan
Research Sucuri, 18 Oct 2024
In our recent investigation, we discovered a new malware campaign targeting WordPress sites through a fake plugin, universal-popup-plugin-v133 , which delivers deceptive browser fix pop-ups. This malware leverages social engineering tact...
- Security implications of WordPress repository access restrictions and plugin closures
Research Patchstack, 18 Oct 2024
Over the past couple of weeks, we’ve noticed an increasing number of plugins not receiving updates through WordPress.org. Some have been banned and others cannot log in to their WordPress.org accounts due to the new login requirement und...
- Critical Vulnerabilities in Ultimate Membership Pro Plugin
Research Patchstack, 17 Oct 2024
This blog post is about Ultimate Membership Pro plugin vulnerabilities. If you’re an Ultimate Membership Pro user, please update the theme and plugin to version 12.8 or higher. About the Ultimate Membership Pro Plugin The plugin Ultimate...
- WooCommerce Security Essentials for Store Owners
Research Sucuri, 10 Oct 2024
Running a WooCommerce store is awesome for your business - it opens up a whole world of opportunities. But let’s be honest, it also comes with some security risks. We’re talking about hackers trying to swipe customer data and nasty malwa...
- The Best WordPress Activity Log Plugins
Research Patchstack, 9 Oct 2024
Are you managing a large WordPress website with the help of a team? Do you constantly find yourself asking, “Who made this change?” Did someone break your WordPress website, and are you looking to get to the root of this issue? If you an...
- Unauthenticated Stored XSS Vulnerability in LiteSpeed Cache Plugin Affecting 6+ Million Sites
Research Patchstack, 2 Oct 2024
This blog post is about the LiteSpeed Cache plugin vulnerability which is originally reported by TaiYou to the Patchstack bug bounty program for WordPress. We are collaborating with the researcher to release the content of this security ...
- WordPress Vulnerability & Patch Roundup September 2024
Research Sucuri, 30 Sep 2024
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- How to Know if Your Website Is Hacked
Research Sucuri, 27 Sep 2024
Whether you manage a gaming blog, an e-commerce platform, or an enterprise-level website you probably want to be able to detect infections when they occur. A hacked website can lead to financial loss, disruption of business operations, a...
- Unpatched SQL Injection Vulnerability in TI WooCommerce Wishlist Plugin
Research Patchstack, 25 Sep 2024
Critical SQL Injection Alert: The TI WooCommerce Wishlist plugin, with over 100,000 active installs, is vulnerable to an unauthenticated SQL injection (CVE-2024-43917).
- Privilege Escalation Vulnerability Patched in Houzez Theme
Research Patchstack, 23 Sep 2024
This blog post discusses about the findings on the Houzez theme and plugins that comes installed with it. If you’re a Houzez user, please update the theme to version 3.3.0 or higher and Houzez Login Register plugin to 3.3.0 or higher.
- Stay Secure: How Patchstack’s vPatches protect your WordPress site against the latest vulnerabilities
Research Patchstack, 18 Sep 2024
WordPress, powering over 40% of websites, is a prime target for cyberattacks. Virtual patches (vPatches) provide immediate protection against vulnerabilities in plugins and themes, ensuring site security while awaiting official fixes.
- 7 Steps to Remove Malware from WordPress
Research Sucuri, 17 Sep 2024
If you’ve ever had your website compromised by malware, you know the sheer panic it can cause. But don’t worry, you’re not alone. More importantly it’s something you can fix! In this guide, we’ll walk you through seven essential steps to...
- The Best WordPress SEO Plugins (Ranked by Quality & Security)
Research Patchstack, 13 Sep 2024
“If you’re running a business, there’s no such thing as page 2 of Google.” Harsh words? No, not really. Since only 0.63% of users actually click through to page 2 of Google, you’re either on page 1… …or you’re nowhere. However, if you’re...
- Woo Skimmer Uses Style Tags and Image Extension to Steal Card Details
Research Sucuri, 12 Sep 2024
This post starts the same way many others do on this blog, and it will be familiar to those who keep up with website security: A client came to us having been notified by their payment processor that credit cards were being stolen from t...
- SQL Injection Vulnerabilities Found in ListingPro Theme and Plugin
Research Patchstack, 12 Sep 2024
This blog post is about ListingPro theme vulnerabilities. If you’re a ListingPro user, please update the theme and plugin to version 2.9.5 or higher. About the ListingPro Theme and Plugin The theme ListingPro (premium version), which has...
- Unpatched Vulnerability in TI WooCommerce Wishlist Plugin
Research WPScan, 9 Sep 2024
A few weeks ago a SQL Injection was discovered in the TI WooCommerce Wishlist plugin. After checking closer we found another entry point, affecting over 100,000 active installs. Despite the severity of this issue, the vendor has not yet ...
- The 6 Best WordPress Security Plugins (+ Do You Really Need One?)
Research Patchstack, 9 Sep 2024
There are thousands of “WordPress security plugins” listed on the official WordPress plugin repository, which claim to offer some security-related functionality and serve some purpose related to securing WordPress. This is not surprising...
- Interview with John Blackbourn
Research Patchstack, 6 Sep 2024
Today we present an interview with John Blackbourn. John is a web developer of 20 years, a leader of projects and teams, and a public speaker. He recently moved into the role of Director of WordPress Security at Human Made.
- Critical Account Takeover Vulnerability Patched in LiteSpeed Cache Plugin
Research Patchstack, 5 Sep 2024
This blog post is about the LiteSpeed plugin vulnerability. If you’re a LiteSpeed user, please update the plugin to at least version 6.5.0.1. Patchstack is the official security partner for LiteSpeed Cache. Patchstack is helping with coo...
- How to Detect & Remove Malware from a WordPress Site
Research Patchstack, 3 Sep 2024
Performing a WordPress malware removal in a way that you can be sure that it’s clean is not an easy task. That’s why a WordPress malware removal can cost over 150 dollars - and that’s not considering lost revenue, wasted ad spend or long...
- WordPress Vulnerability & Patch Roundup August 2024
Research Sucuri, 30 Aug 2024
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.