Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,885 reports kept since 2009. Updated automatically every 10 minutes. Last checked 1 min ago.

  1. SQL Injection Vulnerabilities Found in ListingPro Theme and Plugin

    Research Patchstack, 12 Sep 2024

    This blog post is about ListingPro theme vulnerabilities. If you’re a ListingPro user, please update the theme and plugin to version 2.9.5 or higher. About the ListingPro Theme and Plugin The theme ListingPro (premium version), which has...

  2. Unpatched Vulnerability in TI WooCommerce Wishlist Plugin

    Research WPScan, 9 Sep 2024

    A few weeks ago a SQL Injection was discovered in the TI WooCommerce Wishlist plugin. After checking closer we found another entry point, affecting over 100,000 active installs. Despite the severity of this issue, the vendor has not yet ...

  3. The 6 Best WordPress Security Plugins (+ Do You Really Need One?)

    Research Patchstack, 9 Sep 2024

    There are thousands of “WordPress security plugins” listed on the official WordPress plugin repository, which claim to offer some security-related functionality and serve some purpose related to securing WordPress. This is not surprising...

  4. Interview with John Blackbourn

    Research Patchstack, 6 Sep 2024

    Today we present an interview with John Blackbourn. John is a web developer of 20 years, a leader of projects and teams, and a public speaker. He recently moved into the role of Director of WordPress Security at Human Made.

  5. Critical Account Takeover Vulnerability Patched in LiteSpeed Cache Plugin

    Research Patchstack, 5 Sep 2024

    This blog post is about the LiteSpeed plugin vulnerability. If you’re a LiteSpeed user, please update the plugin to at least version 6.5.0.1. Patchstack is the official security partner for LiteSpeed Cache. Patchstack is helping with coo...

  6. How to Detect & Remove Malware from a WordPress Site

    Research Patchstack, 3 Sep 2024

    Performing a WordPress malware removal in a way that you can be sure that it’s clean is not an easy task. That’s why a WordPress malware removal can cost over 150 dollars - and that’s not considering lost revenue, wasted ad spend or long...

  7. WordPress Vulnerability & Patch Roundup August 2024

    Research Sucuri, 30 Aug 2024

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  8. 12 Best Practices to Secure Your WordPress Login Page

    Research Sucuri, 29 Aug 2024

    WordPress powers a significant portion of websites on the internet. With this popularity comes the need for strict security measures, especially for the login page. These entry points are prime targets for hackers and malicious actors. B...

  9. WordPress Websites Used to Distribute ClearFake Trojan Malware

    Research Sucuri, 22 Aug 2024

    Unfortunately, scams are all over the place, and anybody who has surfed the web should know this. We’ve all gotten phishing emails, or redirected to questionable websites at some point or another. Being on your guard is an important post...

  10. Critical Privilege Escalation in LiteSpeed Cache Plugin Affecting 5+ Million Sites

    Research Patchstack, 21 Aug 2024

    The vulnerability in the LiteSpeed Cache plugin was originally reported by Patchstack Alliance community member John Blackbourn to the Patchstack Zero Day bug bounty program for WordPress. We are collaborating with the researcher to rele...

  11. PrestaShop GTAG Websocket Skimmer

    Research Sucuri, 14 Aug 2024

    During a recent investigation we uncovered another credit card skimmer leveraging a web socket connection to steal credit card details from an infected PrestaShop website. While PrestaShop is not the most popular eCommerce solution for o...

  12. What is Website Monitoring?

    Research Sucuri, 8 Aug 2024

    You rarely hear about a website when everything is working. There’s no applause when pages load fast, forms go through, or checkout works smoothly. But as soon as something breaks (hacked homepage, DNS issue, expired cert, etc.), you not...

  13. We launched Patchstack Academy

    Research Patchstack, 1 Aug 2024

    We’re excited to announce the official launch of Patchstack Academy - your go-to platform for learning about ethical hacking and securing your code 🎉 Why Patchstack Academy? When searching for WordPress security online, most results foc...

  14. Patchstack’s Weekly WordPress Vulnerability Overview - July 24 to 30, 2024

    Research Patchstack, 31 Jul 2024

    Welcome to Patchstack’s WordPress vulnerability overview for the week of July 24 - 30, 2024. As the #1 vulnerability processor in the world, Patchstack brings you this report so you can stay safe even if you don’t use the Patchstack app ...

  15. Real Hackers Explain How and Why WordPress Sites Get Hacked

    Research Patchstack, 31 Jul 2024

    Did you know that hackers can mimic your eCommerce checkout page and steal your revenue without your customers realizing they’re using a fraudulent form? Or, were you aware that one of the easiest ways to attack a site is to exploit a Wo...

  16. WordPress Vulnerability & Patch Roundup July 2024

    Research Sucuri, 29 Jul 2024

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  17. Patchstack’s Weekly WordPress Vulnerability Overview - July 17 to 23, 2024

    Research Patchstack, 24 Jul 2024

    Welcome to Patchstack’s WordPress vulnerability overview for the week of July 17 - 23, 2024. As the #1 vulnerability processor in the world, Patchstack brings you this report so you can stay safe even if you don’t use the Patchstack app ...

  18. Cheese, Cake, and Cybersecurity: Your Quick-Start Guide to Protecting Your WordPress Website

    Research Patchstack, 23 Jul 2024

    One company tells you that you need an antivirus. Another says you’re good with their all-in-one plugin. Your hosting provider keeps going on about server-side things they’re doing. And, at the end of the day, you’re still left with a gl...

  19. Attackers Abuse Swap File to Steal Credit Cards

    Research Sucuri, 19 Jul 2024

    When it comes to website security, sometimes the most innocuous features can become powerful tools in the hands of attackers. Such was the case in a recent incident we investigated, where bad actors exploited the humble swap file to main...

  20. Mastering WordPress File Permissions: A Guide for All Levels

    Research Sucuri, 17 Jul 2024

    File permissions might seem like a small part of managing a WordPress site, but they play a key role in your website’s security and functionality. Incorrect permissions can leave your site vulnerable to attacks, while overly restrictive ...

  21. Patchstack’s Weekly WordPress Vulnerability Overview - July 10 to 16, 2024

    Research Patchstack, 17 Jul 2024

    Welcome to Patchstack’s WordPress vulnerability overview for the week of July 10 - 16, 2024. As the #1 vulnerability processor in the world, Patchstack brings you this report so you can stay safe even if you don’t use the Patchstack app ...

  22. Unauthenticated Privilege Escalation in Profile-Builder plugin

    Research WPScan, 15 Jul 2024

    During a routine audit of various WordPress plugins, we identified some issues in Profile Builder and Profile Builder Pro (50k+ active installs). We discovered an Unauthenticated Privilege Escalation Vulnerability which could allow attac...

  23. Critical Vulnerability Patched in Backup and Staging by WP Time Capsule Plugin

    Research Patchstack, 13 Jul 2024

    This blog post is about the WP Time Capsule plugin vulnerability. If you’re a WP Time Capsule plugin user, please update to at least version 1.22.21. About the Backup and Staging by WP Time CapsulePlugin Backup and Staging by WP Time Cap...

  24. Patchstack’s Weekly WordPress Vulnerability Overview - July 3 to 9, 2024

    Research Patchstack, 10 Jul 2024

    Welcome to Patchstack’s WordPress vulnerability overview for the week of July 3 - 9, 2024. As the #1 vulnerability processor in the world, Patchstack brings you this report so you can stay safe even if you don’t use the Patchstack app (y...

  25. New Variation of WordFence Evasion Malware

    Research Sucuri, 5 Jul 2024

    We recently came across an infected WordPress environment which contained a new variation of WordFence evasion malware using some sneaky tactics to conceal itself from view. The site administrator was reporting some issues with potential...

  26. WordPress User Enumeration: Risks & Mitigation Steps

    Research Sucuri, 3 Jul 2024

    User enumeration is a technique used by attackers to discover valid usernames associated with a CMS or website. By exploiting certain features, bad actors can compile a list of usernames, which can then be used to launch brute force atta...

  27. Patchstack’s Weekly WordPress Vulnerability Overview - June 26 to July 2, 2024

    Research Patchstack, 3 Jul 2024

    Welcome to Patchstack’s WordPress vulnerability overview for the week of June 26 - July 2, 2024. As the #1 vulnerability processor in the world, Patchstack brings you this report so you can stay safe even if you don’t use the Patchstack ...

  28. Polyfill Vulnerability Effect on the WordPress Ecosystem

    Research Patchstack, 3 Jul 2024

    On the 25th of June 2024, Sansec released a security advisory article regarding the Polyfill supply chain attack. Intro Polyfill.js is a popular JavaScript library that provides modern functionality on older browsers that do not natively...

  29. WordPress Core 6.5.5 Security Update - Technical Advisory

    Research Patchstack, 1 Jul 2024

    On the 24th of June 2024, WordPress.org released a security update and recommended users update their sites as soon as possible. This WordPress core 6.5.5 security release addresses 3 different security vulnerabilities that affect multip...

  30. WordPress Vulnerability & Patch Roundup June 2024

    Research Sucuri, 28 Jun 2024

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  31. Patchstack’s Weekly WordPress Vulnerability Overview - June 19 to 25, 2024

    Research Patchstack, 26 Jun 2024

    Welcome to Patchstack’s WordPress vulnerability overview for the week of June 19 - 25, 2024. As the #1 vulnerability processor in the world, Patchstack brings you this report so you can stay safe even if you don’t use the Patchstack app ...

  32. Object Injection vulnerability fixed in SEOPress 7.9

    Research WPScan, 24 Jun 2024

    During a routine audit of various WordPress plugins, we identified a few issues in SEOPress (300k+ active installs). More specifically, we discovered an authentication bug which could allow attackers to access certain protected REST API ...

  33. Decoding the Caesar Cipher Skimmer

    Research Sucuri, 21 Jun 2024

    Over the last several weeks we’ve observed an interesting new variation of “ gtag ” credit card skimming attack with a surprisingly high number of detections so far. As of the time of writing this article we have seen nearly 80 detection...

  34. Patchstack’s Weekly WordPress Vulnerability Overview - June 11 to 18, 2024

    Research Patchstack, 19 Jun 2024

    Welcome to Patchstack’s WordPress vulnerability overview for the week of June 11 - 18, 2024. As the #1 vulnerability processor in the world, Patchstack brings you this report so you can stay safe even if you don’t use the Patchstack app ...

  35. SocGholish Malware: What It Is & How to Prevent It

    Research Sucuri, 18 Jun 2024

    Website malware comes in all shapes and sizes, each with its own unique methods of attack and evasion. One threat making regular headlines is SocGholish, a sophisticated and persistent malware that has been targeting websites for over 7 ...

  36. 2023 Hacked Website & Malware Threat Report

    Research Sucuri, 12 Jun 2024

    Education is essential for defending your website against emerging threats. That’s why we are thrilled to share our 2023 Hacked Website & Malware Threat Report. Disseminating this information to the community helps educate website owners...

  37. Multiple Vulnerabilities in WooCommerce Amazon Affiliates Plugin

    Research Patchstack, 6 Jun 2024

    This blog post is about WooCommerce Amazon Affiliates (WZone) plugin vulnerabilities. If you’re a WooCommerce Amazon Affiliates (WZone) user, please deactivate and delete the plugin since there is still no known patched version. About th...

  38. Hundreds of Websites Targeted by Fake Google Chrome Update Pop-Ups

    Research Sucuri, 5 Jun 2024

    Fake Browser Update campaigns are known for their deceptive tactics used by hackers to trick users into downloading malicious software. These campaigns typically involve injecting malicious code into a website, which then displays a popu...

  39. 10 of the Best Website Security Tools to Stay Ahead of Hackers

    Research WPScan, 5 Jun 2024

    Which website security tools are really necessary for your site? What to consider before investing in new software. 10 must-have tools you can’t skip.

  40. Patchstack’s Weekly WordPress Vulnerability Overview - May 29 to June 04 2024

    Research Patchstack, 5 Jun 2024

    Welcome to Patchstack’s WordPress vulnerability overview for the week of May 29 to June 04 2024. As the #1 vulnerability processor in the world, Patchstack brings you this report so you can stay safe even if you don’t use the Patchstack ...

  41. Make Things New Case Study: Enabling Peace of Mind with Patchstack

    Research Patchstack, 4 Jun 2024

    Patchstack user since: March 2023 When you have as much experience in the marketing world as James Traister and his team at Make Things New, you know your priorities. And for this ambitious team, security and revenue go hand in hand. In ...

  42. Property Portal Marketing Case Study: Staying Safe and Preventing Post-Update Bugs with Patchstack

    Research Patchstack, 3 Jun 2024

    Patchstack user since: June 2023 Raise your hand if you’ve applied a security update to one of your sites, only to see that something got broken in the process. Hand raised? Don’t worry - it’s a WordPress rite of passage. However, that d...

  43. EfficientWP Case Study: Spending Less Time on WordPress Update Management with Patchstack

    Research Patchstack, 3 Jun 2024

    Patchstack user since: July 2022Threats blocked: 6,952 in the last 30 days across 44 websites WordPress updates are no longer just something you set and forget. With the increase in vulnerabilities, updates have become a weekly (and, in ...

  44. ellegaard ID Case Study: From Cleaning Up Hacked Sites to Security by Default

    Research Patchstack, 3 Jun 2024

    Patchstack user since: September 2023 Getting hacked isn’t pleasant in any scenario, but it’s never as critical as when you manage WordPress websites for clients. When Morten Ellegard, the owner of ellegaard ID, a web development and mai...

  45. From Privacy to Exfiltration: Telegram’s Role in Website Malware

    Research Sucuri, 30 May 2024

    Telegram, a name synonymous with secure messaging, has paradoxically become a tool for cybercriminals who abuse the strengths of the platform to target unsuspecting websites. This popular messaging platform, once known for its commitment...

  46. WordPress Vulnerability & Patch Roundup May 2024

    Research Sucuri, 28 May 2024

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  47. Unauthenticated XSS Vulnerability Patched in Slider Revolution Plugin

    Research Patchstack, 28 May 2024

    Slider Revolution came to us with a request to audit their product for potential vulnerabilities since they wanted to make sure that their users’ websites were not vulnerable to an attack. This blog post discusses our audit findings, whi...

  48. Server Side Credit Card Skimmer Lodged in Obscure Plugin

    Research Sucuri, 22 May 2024

    Attackers are always finding new ways to inject malware into websites and new ways to obscure it to avoid detection, but they’re always up to their same old tricks. In this post, we’ll explore how attackers are using a very obscure PHP s...

  49. Critical Vulnerability Patched in UserPro Plugin

    Research Patchstack, 22 May 2024

    This blog post is about the UserPro plugin vulnerabilities. If you’re a UserPro user, please update the plugin to at least version 5.1.9. About the UserPro Plugin The plugin UserPro (premium version), which has over 20,000 sales, is know...

  50. Interview with Mat Rollings AKA stealthcopter

    Research Patchstack, 21 May 2024

    Today we present an interview with one of our most active community members - Mat Rollings. He’s an experienced developer turned application security ‘expert.’ He loves reviewing code and breaking things, making bug bounty hunting his dr...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support