HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,878 reports kept since 2009. Updated automatically every 10 minutes. Last checked 1 min ago.
- Multiple High Severity Vulnerabilities in Ninja Forms Plugin
Research Patchstack, 27 Jul 2023
This blog post is about vulnerabilities in Ninja Forms plugin vulnerabilities. If you’re a Ninja Forms user, please update the plugin to at least version 3.6.26. About the Ninja Forms plugin The plugin Ninja Forms versions 3.6.25 and bel...
- How to Scan a Website for Vulnerabilities
Research Sucuri, 25 Jul 2023
Even the most diligent site owners should consider when they had their last website security check. As our own research indicates, infections resulting from known website vulnerabilities continue to plague website owners. In our 2023 Hac...
- Massive Google Colaboratory Abuse: Gambling and Subscription Scam
Research Sucuri, 18 Jul 2023
This investigation started with a small and quite simple piece of PHP malware found on a hacked website. We located the following PHP code, responsible for injecting spammy links, within a wp-includes.php file: $lines = file('https://4ip...
- Site-Wide Reflected XSS in Freemius WordPress SDK Affecting Millions of Sites
Research Patchstack, 18 Jul 2023
There is a Site-Wide Reflected XSS in the Freemius WordPress SDK - the vulnerability is in versions <= 2.5.9 and it affects millions of sites. This blog post is about the Freemius WordPress SDK vulnerability. If you’re a vendor of a plug...
- Critical Privilege Escalation in HT Mega Plugin Affecting 100k+ Sites
Research Patchstack, 14 Jul 2023
This blog post is about the HT Mega plugin critical vulnerability. If you’re a HT Mega user, please update the plugin to at least version 2.2.1. About the HT Mega plugin The plugin HT Mega (versions 2.2.0 and below, free version), which ...
- Malicious Injection Redirects Traffic via Parked Domain
Research Sucuri, 13 Jul 2023
During a recent investigation, our malware remediation team encountered a variant of a common malware injection that has been active since at least 2017. The malware was found hijacking the website’s traffic, redirecting visitors via a p...
- How to Harden WordPress: A Basic Overview
Research Sucuri, 12 Jul 2023
Out-of-the-box security configurations tend to not be very secure. This is usually true for all software and WordPress is no exception. Best practices suggest you take a few of these steps to harden WordPress and protect your environment...
- New Guide on Secure VPS Configuration
Research Sucuri, 4 Jul 2023
One of the most common problems that we observe among many of our clients is the persistent threat of cross contamination - that is, malware that spreads from one website to another when they are hosted in the same environment. This is p...
- How to Harden WordPress With WP-Config & Avoid Data Exposure
Research Sucuri, 3 Jul 2023
What is wp-config.php? The wp-config.php file is a powerful core WordPress file that is vital for running your website. It contains important configuration settings for WordPress, including details on where to find the database, login cr...
- WordPress Vulnerability & Patch Roundup June 2023
Research Sucuri, 27 Jun 2023
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- Remote Code Execution Backdoor Uses Unicode Obfuscation & Non-Standard File Extensions
Research Sucuri, 22 Jun 2023
Readers of this blog will know that attackers are constantly finding new ways to hide their malware and avoid detection; after all, that’s what good malware does best! We have recently observed attackers leveraging both excessive amounts...
- New WooCommerce Security Best Practices Guide
Research Sucuri, 20 Jun 2023
WooCommerce is a widely used e-commerce platform, powering nearly 6 million online stores worldwide. Its popularity makes it a prime target for cybercriminals looking to exploit vulnerabilities and steal sensitive data and credit card in...
- Website Hacktools: Types, Threats & Detection
Research Sucuri, 15 Jun 2023
When we think about website malware, visible infection symptoms most often come to mind: unwanted ads or pop-ups, redirects to third party sites, or spam keywords in search results. However, in some cases these very symptoms are the resu...
- How to Generate WordPress Salts & Security Keys: Step by Step Instructions
Research Sucuri, 13 Jun 2023
In the realm of WordPress security, there’s a powerful tag team working tirelessly behind the scenes to safeguard your website’s login process. Meet salts and security keys, the cryptographic wonders responsible for protecting the sensit...
- Unauthenticated IDOR to PII Disclosure in WooCommerce Stripe Gateway Plugin
Research Patchstack, 13 Jun 2023
This blog post is about the WooCommerce Stripe Gateway plugin vulnerability. If you’re a WooCommerce Stripe Gateway user, please update the plugin to at least version 7.4.1. About the WooCommerce Stripe Gateway WordPress plugin The plugi...
- How to Update, Install & Remove WordPress Plugins & Themes With WP-CLI
Research Sucuri, 1 Jun 2023
WordPress, like other open-source content management systems, allows you to enhance your website’s appearance and functionality through custom code and third-party components like plugins and themes. It’s these extensions that allow you ...
- How to Secure WordPress Login URL
Research Patchstack, 31 May 2023
WordPress is the world’s most popular content management system, powering millions of websites globally. Its popularity, however, also makes it a prime target for malicious activities, such as brute force attacks, hacking attempts, and u...
- Unauthenticated PHP Object Injection in Gravity Forms Plugin <= 2.7.3
Research Patchstack, 30 May 2023
This blog post is about the security vulnerability in Gravity Forms. If you’re a Gravity Forms user, please update the plugin to at least version 2.7.4. About the Gravity Forms WordPress plugin The plugin Gravity Forms (versions 2.7.3 an...
- How To Prevent Image Hotlinking in WordPress
Research Patchstack, 29 May 2023
Have you ever wondered why some websites display your images without your permission? Have you ever noticed that your website’s speed and performance are affected by other websites linking to your images? Have you ever worried that your ...
- WordPress Vulnerability & Patch Roundup May 2023
Research Sucuri, 29 May 2023
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- CSRF to wp-admin Site Wide XSS in UpdraftPlus Plugin
Research Patchstack, 19 May 2023
This blog post is about the UpdraftPlus plugin vulnerability. If you’re a UpdraftPlus user, please update the plugin to at least version 1.23.4. About the UpdraftPlus WordPress plugin The plugin UpdraftPlus (versions 1.23.3 and below, fr...
- Vulnerability in Essential Addons for Elementor Leads to Mass Infection
Research Sucuri, 18 May 2023
On May 11th, 2023, the very popular WordPress plugin Essential Addons for Elementor released a patch for a critical privilege escalation vulnerability, initially discovered by PatchStack. The technical details of this vulnerability can b...
- How to Install SSL Certificate on WordPress
Research Patchstack, 18 May 2023
This tutorial will cover everything you need to know about SSL certificate and explains how to install SSL certificate on WordPress. It also includes troubleshooting common issues and managing renewals. Let’s dive in and make your WordPr...
- WordPress 6.2.1 Security & Maintenance Release
Research Sucuri, 17 May 2023
On May 16, 2023, the WordPress core team released a crucial update - WordPress 6.2.1. This latest security and maintenance release addresses a number of bug fixes and vulnerability patches, including an unauthenticated Directory Traversa...
- WordPress Core 6.2.1 Security Update - Technical Advisory
Research Patchstack, 17 May 2023
On the 16th of May 2023, the WordPress Core 6.2.1 version was released with a security update. It recommended users update their sites as soon as possible. This WordPress core 6.2.1 security release addresses 5 different security vulnera...
- Websites Defaced with Belarusian Bottled Water Company Content
Research Sucuri, 16 May 2023
It’s not often that we get the opportunity to write about website defacements on this blog. Defacements - where a website homepage is replaced with a hacker logo or some sort of political or religious message - are usually fairly run-of-...
- Critical Privilege Escalation in Essential Addons for Elementor
Research Patchstack, 11 May 2023
This blog post is about the Essential Addons for Elementor plugin vulnerability. If you’re an Essential Addons for Elementor user, please update the plugin to at least version 5.7.2. About the Essential Addons for Elementor WordPress plu...
- How To Perform a WordPress Backup In 3 Simple Methods
Research Patchstack, 10 May 2023
Ensuring your WordPress backup is safe and made correctly is one of the top recommendations for ensuring your WordPress security. Multiple backups allow you to easily restore your website whenever you lose access to it, or it is hacked a...
- Xjquery Wave of WordPress SocGholish Injections
Research Sucuri, 9 May 2023
In November, 2022, my colleague Ben Martin described how hackers were using zipped files and encrypted WordPress options stored in the database to inject SocGholish scripts into compromised WordPress sites. A bit later, we documented min...
- How To Find Out If My WordPress Site Has Vulnerable Plugins?
Research Patchstack, 8 May 2023
Websites made with WordPress usually rely heavily on third-party software components like plugins and themes. Every single day, hackers and security enthusiasts find new vulnerable plugins or vulnerabilities across different WordPress pl...
- Reflected XSS in Advanced Custom Fields Plugins Affecting 2+ Million Sites
Research Patchstack, 5 May 2023
This blog post is about the Advanced Custom Fields free and pro plugin vulnerability. If you’re an Advanced Custom Fields free and pro user, please update the plugin to at least version 6.1.6. The security fix also backported on version ...
- What is XML-RPC? Security Risks, Best Practices, and How to Disable It
Research Sucuri, 4 May 2023
XML-RPC is a protocol that lets remote applications send commands to your site using XML and HTTP. In WordPress, it works through the xmlrpc.php file and was first created so tools like early mobile apps, desktop blogging clients, and re...
- What is Steganography? (Or, How Hackers Hide Malware On Websites)
Research Sucuri, 2 May 2023
As a child, I loved sending secret messages to my friends using invisible ink. A quick squeeze of lemon juice was all I needed to jot down my secret message. When combined with a simple heat source (I used the heat of the wood stove), th...
- 10 WooCommerce Security Tips To Keep Your Site Secure
Research Patchstack, 2 May 2023
This article will give you 10 important WooCommerce security tips to keep your site protected. Running an eCommerce business can be both challenging and rewarding, but it also comes with many risks and responsibilities. One of the most i...
- Critical Easy Digital Downloads Vulnerability
Research Patchstack, 2 May 2023
This security advisory is written about a critical Easy Digital Downloads vulnerability originally discovered by Nguyen Anh Tien and reported to us through our bug bounty program. Patchstack users have received a vPatch to protect their ...
- WordPress Vulnerability & Patch Roundup April 2023
Research Sucuri, 27 Apr 2023
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- WP-CLI: How to Connect to WordPress via SSH
Research Sucuri, 25 Apr 2023
The WordPress admin dashboard, though intuitive and feature-rich, can be time-consuming to explore. If you’re looking for a more direct approach to website management, consider giving the WordPress Command Line Interface (WP-CLI) a try! ...
- Massive Abuse of Abandoned Eval PHP WordPress Plugin
Research Sucuri, 19 Apr 2023
Attackers are always finding new and creative ways to compromise websites and maintain their foothold in environments. This is frequently done via the use of backdoors: PHP scripts designed to allow attackers access and control even afte...
- Critical Unauthenticated SQL Injection in Quiz And Survey Master <= 8.1.4
Research Patchstack, 18 Apr 2023
This blog post is about the Quiz And Survey Master plugin vulnerability. If you’re a Quiz And Survey Master user, please update the plugin to at least version 8.1.5. About the Quiz And Survey Master WordPress plugin The plugin Quiz And S...
- How I Started Selling WordPress Care Plans To My Clients
Research Patchstack, 14 Apr 2023
This blog post is written about Sander’s experience and how he started to sell WordPress care plans with the help of Patchstack. Hey there! Sander here - you might recognize me from the Patchstack support channel. In this article, I’ll s...
- How To Add Uptime Monitoring on WordPress Website?
Research Patchstack, 14 Apr 2023
Did you know that, on an average, every hour of downtime causes revenue loss of between three to four hundred thousand dollars for 25% of businesses globally? Yes, you read that right! In today’s hyper-connected digital landscape, every ...
- Limit Login Attempts Vulnerability - Patch Now!
Research Sucuri, 12 Apr 2023
On April 11th, 2023, a software update was released to patch a severe vulnerability within the Limit Login Attempts WordPress security plugin. With over 600,000 installations, it’s among the most popular WordPress plugins in use to help ...
- Patchstack Weekly #66: How To Secure Your Code Against Insecure Inclusion Bugs
Research Patchstack, 11 Apr 2023
Welcome to the Patchstack Weekly Security Update, Episode 66! This update is for week 15 of 2023. This week’s knowledge share is about a rare but serious security bug that can be found in any PHP application. Luckily it is easy to avoid ...
- Balada Injector: Synopsis of a Massive Ongoing WordPress Malware Campaign
Research Sucuri, 6 Apr 2023
Our team at Sucuri has been tracking a massive WordPress infection campaign since 2017 - but up until recently never bothered to give it a proper name. Typically, we refer to it as an ongoing long lasting massive WordPress infection camp...
- Hacked Website Threat Report - 2022
Research Sucuri, 5 Apr 2023
Education is crucial in defending your website against emerging threats. That’s why we are thrilled to share our 2022 Website Threat Research Report. Disseminating this information to the community helps educate website owners about the ...
- WordPress Source Code Exposed Online
Research Patchstack, 1 Apr 2023
Early this morning the WordPress source code was found exposed online. The most popular, widest used, and massively successful web application project WordPress, that powers more websites than any other technology had every major and min...
- High Severity Vulnerability in WordPress Elementor Pro Patched
Research Sucuri, 31 Mar 2023
On March 22nd, 2023 a security patch was issued for the popular website builder plugin Elementor Pro. Website administrators using this plugin should immediately patch to at least version 3.11.7 to avoid a potential website compromise. T...
- WordPress Vulnerability & Patch Roundup March 2023
Research Sucuri, 30 Mar 2023
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- Critical Elementor Pro Vulnerability Exploited
Research Patchstack, 30 Mar 2023
This security advisory is written about a critical Elementor Pro vulnerability originally disclosed by NinTechNet. Patchstack users have received a vPatch to protect their site against this vulnerability. Vulnerability information On Mar...
- The Top 10 Most Dangerous Types of Injection Attacks
Research Sucuri, 28 Mar 2023
When it comes to protecting your website from bad actors, there’s one threat you should be aware of: injection attacks . These attacks target weaknesses in your website’s security and are unfortunately quite common. In fact, the well-kno...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.