HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,885 reports kept since 2009. Updated automatically every 10 minutes. Last checked 1 min ago.
- Is WordPress Secure? Everything You Need to Know
Research Patchstack, 17 Dec 2023
“WordPress is insecure because it is open source.” This common misconception assumes open-source software is more vulnerable simply because anyone can see the code and find flaws. However, this is not the case. Open-source software can b...
- Analysis of the Fake WordPress CVE-2023-46182 Patch Plugin & Phishing Campaign
Research Sucuri, 14 Dec 2023
On December 1, 2023, several security researchers reported about a new phishing campaign targeting WordPress administrators. WordPress sites owners had started receiving emails from WordPress.com with the following message: “The WordPres...
- How to Protect WordPress Against DDoS Attacks
Research Patchstack, 14 Dec 2023
One of the major challenges in cloud development is how to protect your applications from DDoS attacks. In this article, you will learn practical strategies you can use to protect WordPress against DDoS attacks. A Distributed Denial of S...
- Critical RCE Vulnerability Patched in Backup Migration Plugin
Research Sucuri, 13 Dec 2023
On December 6th, 2023, the WordPress plugin Backup Migration received a critical security patch for a remote code execution vulnerability. Details were released five days later after users were given an opportunity to install the patch, ...
- WPScan Intro: How to Scan for WordPress Vulnerabilities
Research Sucuri, 12 Dec 2023
In this post, we will look at how to use WPScan as a WordPress vulnerability scanner . This security tool provides you with a better understanding of your WordPress website and any vulnerabilities that may be present in your environment....
- How to Avoid Caching Sensitive Information In WordPress
Research Patchstack, 12 Dec 2023
In this article, you will discover how to avoid caching sensitive information in WordPress, and why it is crucial for your site’s safety. Are you using caching to boost your WordPress site’s performance? Did you know it is possible to ac...
- Multiple Vulnerabilities Patched in Themify Ultra Theme
Research Patchstack, 12 Dec 2023
This blog post is about Themify Ultra theme vulnerability. If you’re a Themify Ultra user, please update the theme to at least version 7.3.6. About the Themify Ultra Theme The theme Themify Ultra (premium version), which is estimated to ...
- How to Quickly Change (Or Reset) WordPress Password
Research Patchstack, 8 Dec 2023
Looking to change or reset your WordPress password? You’ve come to the right place. In some cases, the standard password reset via email may not work - if you no longer have access to the email address associated with your WordPress user...
- Critical Vulnerability in Elementor Affecting 5+ Million Websites
Research Patchstack, 8 Dec 2023
The vulnerability in Elementor was originally reported by Hồng Quân (luk6785 at VNPT-VCI) to our alliance program. We are collaborating with the researcher to release the content of this security advisory article. This blog post is about...
- 40 New Domains of Magecart Veteran ATMZOW Found in Google Tag Manager
Research Sucuri, 7 Dec 2023
Hackers like Google Tag Manager: millions of sites use it, and they can inject custom scripts and HTML code via a script from the highly trusted domain googletagmanager.com . In order to create a new container and abuse Google Tag Manage...
- WordPress 6.4.2 Security Release
Research Patchstack, 6 Dec 2023
WordPress 6.4.2 has been released on December 6th, 2023, which includes an important security fix. This security fix addresses a potential security issue that can only be exploited if another vulnerability (PHP object injection) is alrea...
- Common Website Hacking Techniques
Research Sucuri, 6 Dec 2023
Website hacking - the act of exploiting weaknesses to gain unauthorized access to a website, database, cPanel, or admin dashboard - is a reality that some webmasters struggle with. In the hands of bad actors, automated hack tools and exp...
- How To Disable PHP Execution and Directory Browsing in WordPress?
Research Patchstack, 5 Dec 2023
In this article, you can learn how to disable PHP execution and directory browsing in WordPress to enhance your WordPress site security. Many attackers deploy automated robots on the internet to scan and exploit vulnerabilities on the in...
- Fake CVE Phishing Campaign Tricks WordPress Users Into Installing Malware
Research Patchstack, 3 Dec 2023
For the past couple of days, the Patchstack team has been monitoring a mass-scale phishing campaign with multiple variants of phishing emails going around that are notifying users about a supposed security vulnerability in their WordPres...
- How To Redirect WordPress from HTTP to HTTPs
Research Patchstack, 29 Nov 2023
This is a practical article that helps you to redirect WordPress from HTTP to HTTPs. HTTP and HTTPS are two protocols that are used to transfer data between a web browser and a web server. The main difference between HTTP and HTTPS is th...
- Thrive Theme Vulnerability: Dismiss Tooltip to Privilege Escalation
Research Patchstack, 29 Nov 2023
This blog post is about a premium Thrive Theme vulnerability. If you’re a premium Thrive Theme user, please update the plugin to at least version 3.24.0. About the Thrive Theme The theme Thrive (premium version), which is estimated to ha...
- Patchstack Launches New Firewall Engine, Advanced Hardening Module & More
Research Patchstack, 28 Nov 2023
Today, we’re excited to announce the next generation of Patchstack firewall engine. The new engine is engineered to provide the most efficient application layer protection possible, with even greater vulnerability coverage and industry-l...
- WordPress Vulnerability & Patch Roundup November 2023
Research Sucuri, 24 Nov 2023
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- Authenticated Stored XSS in WooCommerce and Jetpack Plugin
Research Patchstack, 15 Nov 2023
This blog post is about the WooCommerce and Jetpack plugin vulnerability. If you’re a WooCommerce and Jetpack user, please update the plugin to at least version 8.2.0 and 12.8-a.3 respectively. About the WooCommerce and Jetpack plugin Th...
- New Email Course: Common Website Threats & Malware
Research Sucuri, 14 Nov 2023
The digital world isn’t all rainbows, unicorns, and cat gifs; it also has a dark side. As threats become increasingly sophisticated, website owners and administrators need to up their game. That’s why we’ve created this tailored email co...
- How To Protect WordPress Against Brute Force Attacks
Research Patchstack, 13 Nov 2023
Brute force attack is arguably one of the most common and potentially dangerous threats to WordPress websites. A brute force attack involves hackers trying to guess your WordPress login credentials by repeatedly submitting different comb...
- How to Harden & Secure a Website (12 Steps)
Research Sucuri, 11 Nov 2023
Originally published: November 11, 2023 by Rianna MacLeod Attackers don’t care what platform you use. WordPress, Magento, Joomla, Drupal - every site is a potential target if it’s left exposed. Once a vulnerability is publicly disclosed ...
- Patchstack Is Introducing Patchstack Priority
Research Patchstack, 8 Nov 2023
Over the past 6 months, we’ve been building, testing and fine-tuning a new vulnerability scoring system called Patchstack Priority to provide a more accurate representation of the seriousness of security vulnerabilities. The goal? Help W...
- Arbitrary Attachment Render to XSS in Elementor Plugin
Research Patchstack, 8 Nov 2023
This blog post is about an Elementor plugin vulnerability. If you’re an Elementor user, please update the plugin to at least version 3.16.5. About the Elementor Plugin The plugin Elementor (versions <= 3.16.4, free version), which has ov...
- Black Friday & Cyber Monday Ecommerce Security Threats
Research Sucuri, 7 Nov 2023
Consumers spent a whopping $35.3 billion during last year’s cyber week shopping season. With Cyber Monday accounting for $11.3 billion in revenue alone, this period remains one of the biggest online shopping events of the year. Unfortuna...
- New Hacked Database Guide
Research Sucuri, 2 Nov 2023
Your website’s database is a treasure trove of valuable information. However, this also makes it a prime target for hackers looking to steal sensitive data or modify your site’s content and behavior. The unfortunate reality is that a com...
- WordPress Vulnerability & Patch Roundup October 2023
Research Sucuri, 30 Oct 2023
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- Patchstack Partners With Cloudways
Research Patchstack, 26 Oct 2023
We’re happy to announce a new strategic partnership with Cloudways. This week, Cloudways launched their vulnerability scanner powered by Patchstack’s database, giving their customers visibility into potential security issues with their W...
- FakeUpdateRU Chrome Update Infection Spreads Trojan Malware
Research Sucuri, 25 Oct 2023
Fake Google chrome update malware, often associated with the notorious SocGholish infection, is something that we have been tracking for a number of years. It is one of the most common types of website malware. It tricks unsuspecting use...
- How to Secure the WordPress Login Page
Research Sucuri, 24 Oct 2023
Given that WordPress powers millions of websites worldwide, it’s no surprise that it’s a prime target for malicious activities ranging from brute force attacks and hacking attempts to unauthorized access - all of which can wreak havoc on...
- Shifting Malware Tactics & Use of Non-Executable .txt & .log Files
Research Sucuri, 17 Oct 2023
The malware landscape is constantly evolving - and bad actors are always devising new techniques to evade detection. Our analysts most commonly find website malware nestled within JavaScript or PHP files, which can be directly executed b...
- WordPress Core 6.3.2 Security Update - Technical Advisory
Research Patchstack, 13 Oct 2023
On the 12th of October 2023, WordPress.org released a security update and recommended users update their sites as soon as possible. This WordPress core 6.3.2 security release addresses 7 different security vulnerabilities and 1 potential...
- Pre-Auth Arbitrary File Upload in User Submitted Posts Plugin
Research Patchstack, 12 Oct 2023
This blog post is about the User Submitted Posts plugin vulnerability. If you’re a User Submitted Posts user, please update the plugin to at least version 20230914. About the User Submitted Posts Plugin The plugin User Submitted Posts (v...
- How To Block IPs, Countries, and Regions For WordPress
Research Patchstack, 10 Oct 2023
This article will focus on how to block IPs, countries, and regions for Your WordPress website. In this article, we will learn how to filter out unwanted visitors from your website based on their IP addresses or locations. There are seve...
- Balada Injector Targets Unpatched tagDiv Plugin, Newspaper Theme & WordPress Admins
Research Sucuri, 6 Oct 2023
In the middle of September 2023, vulnerability advisory resources disclosed the details of an Unauthenticated Stored XSS vulnerability in the tagDiv Composer (the companion plugin for the popular tagDiv premium themes Newspaper and Newsm...
- Case Study: When Your Premium WordPress Theme Is More Than You Bargained For
Research Patchstack, 6 Oct 2023
UPDATE: We want to thank ThemeForest for reacting swiftly to our report, and for removing the vulnerable premium theme mentioned here from their marketplace.Recently a friend of mine asked me to set up a WordPress site for her using a pr...
- Optimizing WordPress: Security Beyond Default Configurations
Research Sucuri, 3 Oct 2023
Default configurations in software are not always the most secure. For example, you might buy a network-attached home security camera from your friendly neighborhood electronics store. While these are handy to keep an eye on your propert...
- WordPress Vulnerability & Patch Roundup September 2023
Research Sucuri, 28 Sep 2023
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- How To Limit Login Attempts on WordPress (+ Should You?)
Research Patchstack, 28 Sep 2023
WordPress is (by far) the most popular content management system - and of course, as big advocates ourselves, it’s easy to see why. That said, powering more than 40% of all websites on the internet also means WordPress sites are targeted...
- Two Paths to Privilege Escalation Vulnerability In The Simple Membership Plugin
Research Patchstack, 27 Sep 2023
This blog post is about the vulnerability in the Simple Membership plugin. If you’re a Simple Membership user, please update the plugin to at least version 4.3.5. About the Simple Membership Plugin The plugin Simple Membership (versions ...
- What Is ‘Error Establishing a Database Connection’ & How To Fix It in WordPress
Research Sucuri, 26 Sep 2023
Originally published: September 26, 2023 by Rianna MacLeod Experiencing the ‘ Error Establishing a Database Connection ‘ on your WordPress website? This common error indicates that your site is unable to connect to its database, renderin...
- How to Find & Fix Japanese SEO Spam
Research Sucuri, 19 Sep 2023
Japanese SEO Spam, also known as “Japanese keyword hack” or “Japanese SEO poisoning,” is a spammy search engine optimization technique used by black hat SEO artists to make a website show up in search engine results for spam keywords in ...
- Authenticated Privilege Escalation Vulnerability in Essential Addons for Elementor
Research Patchstack, 15 Sep 2023
This blog post is about the vulnerability in Essential Addons for Elementor. If you’re an Essential Addons for Elementor user, please update the plugin to at least version 5.8.9. About the Essential Addons for the Elementor plugin The pl...
- What is Secure Shell (SSH) & How to Use It: Security & Best Practices
Research Sucuri, 14 Sep 2023
Navigating your WordPress site’s dashboard can provide you with significant control over your website’s functionality and appearance. Yet it won’t offer a direct interaction or management of your server. This is where Secure Shell Access...
- Patchstack Is FREE On the Official WordPress Repository
Research Patchstack, 14 Sep 2023
Yes, Patchstack is FREE to download and install on the official WordPress repository. It always has been. Unfortunately, not everyone new to WordPress is aware of this and there are different reasons why. Automattic (the company behind W...
- Decoding Magecart: Credit Card Skimmers Concealed Through Pixels & Images
Research Sucuri, 12 Sep 2023
MageCart infections most often come in the form of complex, obfuscated JavaScript injected into Magento database tables such as core_config_data , or as malicious plugins or core file injections installed into WordPress / WooCommerce env...
- Unauthenticated PHP Object Injection in Flatsome Theme <= 3.17.5
Research Patchstack, 6 Sep 2023
This blog post is about the Flatsome theme vulnerability. If you’re a Flatsome user, please update the plugin to at least version 3.17.6. About the Flatsome Theme The theme Flatsome (versions 3.17.5 and below, premium version), which is ...
- Bogus URL Shorteners Go Mobile-Only in AdSense Fraud Campaign
Research Sucuri, 5 Sep 2023
Since September 2022, our team has been tracking a bogus URL shortener redirect campaign that started with just a single domain: ois[.]is. By the beginning of 2023, this malware campaign had expanded to over a hundred domain names to red...
- WordPress Vulnerability & Patch Roundup August 2023
Research Sucuri, 31 Aug 2023
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- Critical Arbitrary File Upload Patched in Forminator Plugin
Research Patchstack, 31 Aug 2023
This security advisory is written about a critical Forminator vulnerability initially disclosed by MEHMET KELEPÇE. Patchstack users have received a vPatch to protect their site against this vulnerability. This blog post is about the Form...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.