HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,885 reports kept since 2009. Updated automatically every 10 minutes. Last checked 1 min ago.
- Exploring the Unknown: Beneath the Surface of Unpatched WordPress SSRF
Research Patchstack, 17 May 2024
This is a blog post about research of an additional vulnerability scenario of the root cause that led to the publicly known WordPress Core Blind SSRF. More affected components were found that may affect hundreds of plugins in the wild. W...
- Critical Vulnerabilities Found in XStore Theme and Plugin
Research Patchstack, 14 May 2024
This blog post is about the XStore theme and plugin vulnerabilities. If you’re an XStore user, please update the theme to at least version 9.3.9 and the plugin to at least version 5.3.9. About the XStore Theme and Plugin The theme XStore...
- A persistent twist in the current Malware Campaign
Research WPScan, 13 May 2024
Recently while covering malware campaigns exploiting the LiteCache and WP‑Automatic WordPress plugins, we found that attackers were installing php‑everywhere, a plugin that allows users to run arbitrary PHP code in their site’s posts. Th...
- What is HTTP Error 502 Bad Gateway & How to Troubleshoot It
Research Sucuri, 9 May 2024
Website errors can be a real test of patience. One common culprit is the 502 bad gateway error. Known for its ubiquity across the web, it doesn’t discriminate between small WordPress sites or well-known services like Gmail, Twitter, or I...
- High Priority Vulnerabilities Patched in Uncode Core Plugin
Research Patchstack, 7 May 2024
This blog post is about the Uncode Core plugin vulnerabilities. If you’re a Uncode user, please update the core plugin to at least version 2.8.9. About the Uncode Core Plugin The plugin Uncode Core (premium version) is a required plugin ...
- Surge of JavaScript Malware in sites with vulnerable versions of LiteSpeed Cache Plugin
Research WPScan, 3 May 2024
If you’ve recently encountered the admin user wpsupp‑user on your website, it means it’s being affected by this wave of infections. Identifying Contamination Signs: The malware typically injects code into critical WordPress files, often ...
- Mal.Metrica Redirects Users to Scam Sites
Research Sucuri, 2 May 2024
One of our analysts recently identified a new Mal.Metrica redirect scam on compromised websites, but one that requires a little bit of effort on the part of the victim. It’s another lesson for web users to be careful what they click on, ...
- WordPress Vulnerability & Patch Roundup April 2024
Research Sucuri, 29 Apr 2024
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- The Best WordPress Backup Plugins and Services in 2025 (Ranked by Security)
Research Patchstack, 24 Apr 2024
Disclaimer: Please note that we always recommend to use backup services offered by your hosting provider. Plugin-based solutions should only be used for redundancy or when there is no other option. With 46% of all websites running on Wor...
- The 12 Best WordPress Form Plugins (Ranked by Quality & Security)
Research Patchstack, 19 Apr 2024
Forms are essential for any website that needs to collect information from visitors, whether it’s for lead generation, feedback, surveys, quizzes, or payments. But with so many WordPress form plugins available, how do you know which one ...
- JavaScript Malware Switches to Server-Side Redirects & DNS TXT Records as TDS
Research Sucuri, 18 Apr 2024
Last August we documented a malware campaign that was injecting malicious JavaScript code into compromised WordPress sites to redirect site visitors to VexTrio domains. The most interesting thing about that malware was how it used dynami...
- WordPress Maintenance: Tasks & Best Practices
Research Sucuri, 16 Apr 2024
If you’re managing a WordPress site, it’s crucial to ensure it runs smoothly and securely. Many site owners worry that WordPress maintenance is a complex chore that requires a ton of technical expertise, but that’s not entirely true. Thi...
- WordPress File Permissions - The Complete Guide
Research Patchstack, 15 Apr 2024
If you’re a WordPress user, then you may already know that WordPress needs certain file permissions to function properly, such as reading, writing, and executing files. If you misconfigure these permissions, it could put your site at ris...
- How to Use CAPTCHAs on WordPress to Protect Your Site from Bots and Spammers
Research Patchstack, 15 Apr 2024
According to a report by Imperva Threat Research, bots accounted for 47% of all web traffic in 2022, with 27.7% of them being identified as malicious. That means that one in four visitors to your site could be a hacker, a spammer, or a s...
- Credit Card Skimmer Hidden in Fake Facebook Pixel Tracker
Research Sucuri, 11 Apr 2024
In recent months, we have encountered a number of cases where attackers inject malware into website software that allows for custom or miscellaneous code - for example, the miscellaneous scripts area of the Magento admin panel, or WordPr...
- Critical Vulnerabilities Patched in REHub Theme and Plugin
Research Patchstack, 3 Apr 2024
This blog post is about the REHub theme and plugin vulnerabilities. If you’re a REHub user, please update the plugin to at least version 19.6.2 on both the theme and the plugin. About the REHub Theme and Plugin The theme REHub (premium v...
- Magento Shoplift: Ecommerce Malware Targets Both WordPress & Magento CMS
Research Sucuri, 2 Apr 2024
We often write about malware that steals payment information from sites built with Magento and other types of e-commerce CMS. However, WordPress has become a massive player in ecommerce as well, thanks to the adoption of Woocommerce and ...
- WordPress Vulnerability & Patch Roundup March 2024
Research Sucuri, 25 Mar 2024
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- Sign1 Malware: Analysis, Campaign History & Indicators of Compromise
Research Sucuri, 20 Mar 2024
A new client recently came to us reporting seemingly random pop ups occurring on their website. While it was clear that there was something amiss with the website it was difficult to reproduce the issue. However, by inspecting our server...
- Critical Vulnerabilities Patched in WordPress Automatic Plugin
Research Patchstack, 19 Mar 2024
This blog post is about the Automatic plugin vulnerabilities. If you’re an Automatic user, please update the plugin to at least version 3.92.1. About the Automatic Plugin The plugin Automatic (premium version), which is estimated to have...
- What is .htaccess Malware? (Detection, Symptoms & Prevention)
Research Sucuri, 15 Mar 2024
The .htaccess file is notorious for being targeted by attackers. Whether it’s using the file to hide malware, redirect search engines to other sites with black hat SEO tactics, or inject content - the range of possibilities for misuse is...
- Sucuri WordPress Plugin Updates for 2024
Research Sucuri, 13 Mar 2024
At Sucuri, we believe in making the internet safe for everyone. One way we show this is through our free WordPress security plugin. The Sucuri WordPress plugin is available for download in the WordPress repository. It comes with a range ...
- Critical Vulnerability Found in GOTMLS Plugin
Research Patchstack, 12 Mar 2024
The vulnerability in the GOTMLS plugin was originally reported by stealthcopter to the Patchstack bug bounty program for WordPress. We are collaborating with the researcher to release the content of this security advisory article. This b...
- New Malware Campaign Found Exploiting Stored XSS in Popup Builder < 4.2.3
Research Sucuri, 7 Mar 2024
In January, my colleague reported about a new Balada Injector campaign found exploiting a recent vulnerability in the widely-used Popup Builder WordPress plugin which was initially disclosed back in November, 2023 by Marc Montpas. In the...
- From Web3 Drainer to Distributed WordPress Brute Force Attack
Research Sucuri, 5 Mar 2024
Two weeks ago we discussed a new development in website hacks: Web3 crypto wallet drainers. We’ve been closely following the most significant variant which injects drainers using the external cachingjs/turboturbo.js script. Our SiteCheck...
- New Wave of SocGholish Infections Impersonates WordPress Plugins
Research Sucuri, 1 Mar 2024
SocGholish malware, otherwise known as “fake browser updates”, is one of the most common types of malware infections that we see on hacked websites. This long-standing malware campaign leverages a JavaScript malware framework that has be...
- WordPress Vulnerability & Patch Roundup February 2024
Research Sucuri, 29 Feb 2024
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- XSS Vulnerability in LiteSpeed Cache Plugin Affecting 4+ Million Sites
Research Patchstack, 27 Feb 2024
This blog post is about the LiteSpeed plugin vulnerability. If you’re a LiteSpeed user, please update the plugin to at least version 5.7.0.1. About the LiteSpeed Cache Plugin The plugin LiteSpeed Cache (free version), which has over 4 mi...
- Understanding XML-RPC in WordPress (What It Is, Security Risks, How to Disable It)
Research Patchstack, 26 Feb 2024
What is XML-RPC, and why should you be concerned with disabling it in WordPress? There’s a price to be paid for popularity. While WordPress’s phenomenal rise in popularity has resulted in 810 million websites being built with it, and a s...
- WordPress Hacked: What to Do When Your Site is Compromised
Research Sucuri, 23 Feb 2024
OK - your WordPress site is hacked. Now what? Questions we frequently get from new users are, “Why was my WordPress site hacked?” and “What should I do after a WordPress hack?” Of course, these are reasonable questions to ask; it’s extre...
- Web3 Crypto Malware: Angel Drainer Overview, Variants & Stats
Research Sucuri, 21 Feb 2024
Since January 2024, there has been a notable surge in attacks by a novel form of website malware targeting Web3 and cryptocurrency assets. This malware, spread across multiple campaigns, uses crypto drainers to steal and redistribute ass...
- Announcing the Patchstack WordPress Security Weekly Newsletter
Research Patchstack, 21 Feb 2024
When we talk about WordPress websites, we often talk about development. But security is just as crucial. After numerous requests, we’ve decided to revive our previous security newsletter, taking it one step further. We’re excited to anno...
- Critical RCE Patched in Bricks Builder Theme
Research Patchstack, 19 Feb 2024
The vulnerability in the Bricks Builder Theme was originally reported by snicco to the Patchstack bug bounty program for WordPress. We are collaborating with the researcher to release the content of this security advisory article. This b...
- Remote Access Trojan (RAT): Types, Mitigation & Removal
Research Sucuri, 16 Feb 2024
Remote Access Trojans (RATs) are a serious threat capable of giving attackers control over infected systems. This malware stealthily enters systems (often disguised as legitimate software or by exploiting a vulnerability in the system) a...
- How To Add Two-Factor Authentication To WordPress
Research Patchstack, 7 Feb 2024
Are you worried that a password breach may have compromised your credentials? No matter whether you answered ‘yes’ or ‘no’ to that question, you should still implement multi-factor authentication to your WordPress sites. In this post, yo...
- How to Stop WordPress Spam Comments: A Comprehensive Guide
Research Patchstack, 5 Feb 2024
WordPress is a versatile and widely used content management system, and as a result, has become a prime target for spam comments. In this blog post, we’ll dive into how to stop WordPress spam comments. In recent times, the threat has int...
- Guide to Forcing User Logout in WordPress: When and How
Research Patchstack, 5 Feb 2024
Did you leave your WordPress account logged in on a shared computer? Are you worried that someone is using your account without your permission? Worry no more! Forcing user logout in WordPress is a feature that will help put your mind at...
- WordPress 6.4.3 Security Release
Research Patchstack, 31 Jan 2024
WordPress 6.4.3 was released on January 30th, 2024, which includes two low-severity security fixes. This security fix addresses two potential security issues. The first one is an Administrator+ arbitrary PHP file upload on the plugin and...
- Is WooCommerce Safe? Exploring Vulnerabilities and Security Measures
Research Patchstack, 31 Jan 2024
Many businesses rely on WooCommerce for their e-commerce store, but have you considered whether is WooCommerce safe to use? E-commerce sales hit $6.3 trillion in 2023, and 20% of all retail sales were made online. If you run an e-commerc...
- Vulnerability & Patch Roundup January 2024
Research Sucuri, 30 Jan 2024
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- How to Find, Change & Protect the WordPress Login URL: A Beginner’s Guide
Research Sucuri, 25 Jan 2024
If you’ve recently launched a WordPress website, you might be asking, “ How do I log in to WordPress? ” or “ Where is my WordPress login located? ” Don’t worry - you’re not alone, and these are essential questions to ask. Understanding w...
- Fixing Website Hosting Issues: “This Account Has Been Suspended”
Research Sucuri, 24 Jan 2024
Experiencing a “ This account has been suspended ” warning on your website can be both confusing and alarming. This message means that your hosting provider has put your site on a temporary hold. The reasons for an account suspension can...
- Thousands of Sites with Popup Builder Compromised by Balada Injector
Research Sucuri, 10 Jan 2024
On December 11, 2023 WPScan published Marc Montpas’ research on the stored XSS vulnerability in the popular Popup Builder plugin (200,000+ active installation) that was fixed in version 4.2.3. A couple of days later, on December 13th, th...
- AI Engine Plugin Affected by Critical Vulnerability
Research Patchstack, 9 Jan 2024
This blog post is about an AI Engine plugin vulnerability. If you’re an AI Engine user, please update the plugin to at least version 1.9.99. About the AI Engine Plugin The plugin AI Engine (free version), which has over 50,000 active ins...
- How To Change The Default WordPress Login URL?
Research Patchstack, 3 Jan 2024
Did you know that attackers can use several techniques to gain full access to your WordPress site if you use the default login URL? In this article, we will learn how to change the default WordPress Login URL to a custom secure URL. At P...
- WordPress Vulnerability & Patch Roundup December 2023
Research Sucuri, 28 Dec 2023
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- New Guide: Broken Access Control
Research Sucuri, 26 Dec 2023
The complexity of modern websites exposes countless potential vulnerabilities to lurking attackers. One of the most underestimated threats? Broken Access Control (BAC). The risk lies within the very machinations of your website - the sys...
- MageCart WordPress Plugin Injects Malicious User & Credit Card Skimmer
Research Sucuri, 21 Dec 2023
One of our analysts recently found an interesting malicious plugin injected into a WordPress / WooCommerce ecommerce website which both creates and conceals a bogus administrator user. It was also found injecting sophisticated credit car...
- Critical SQL Injection Found in Porto Theme’s Plugin
Research Patchstack, 20 Dec 2023
This blog post is about the Porto Theme’s plugin vulnerability. If you’re a Porto Theme user, please update the plugin to at least version 2.12.1. About the Porto Theme’s Plugin The plugin Porto Theme - Functionality (premium version) is...
- How to Backup WooCommerce Store?
Research Patchstack, 18 Dec 2023
This blog post explains how to backup WooCommerce store since having a good WooCommerce backup solution in place could potentially save your entire business one day. With 1 in 25 WordPress sites being hacked in 2023, how long do you feel...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.