Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
  • Immediate Help
Login
Login

New Customer?

Sign up now.
  • Submit a ticket
  • Knowledge base
  • Chat now

Browsing Category

WordPress Security

666 posts
Reverse String WooCommerce
  • Ecommerce Security
  • Sucuri Labs
  • Website Malware Infections
  • Website Security
  • WordPress Security

Reverse String WooCommerce WordPress Credit Card Swiper

  • Ben Martin
  • July 27, 2020
As 2020 continues to be the worst year in almost anybody’s lifetime, allow me to take this opportunity to stoke the fires of your existential…
Read the Post
Fake WordPress Plugin SiteSpeed Hosts Malicious Ads & Backdoors
  • Sucuri Labs
  • Website Security
  • WordPress Security

Fake WordPress Plugin SiteSpeed Serves Malicious Ads & Backdoors

  • Krasimir Konov
  • July 16, 2020
Fake WordPress plugins appear to be trending as an effective way of establishing a foothold on compromised websites. During a recent investigation, we discovered a…
Read the Post
Pirated WordPress & Magento Plugins
  • Ecommerce Security
  • Magento Security
  • Website Malware Infections
  • Website Security
  • WordPress Security

Pirated WordPress Plugins Bundled with Backdoors

  • Luke Leal
  • July 8, 2020
One widespread belief among webmasters is that attackers typically only compromise websites in a couple of ways: by exploiting vulnerabilities or stealing login credentials. Although…
Read the Post
PinnacleCart Server-Side Skimmer & Backdoor
  • Ecommerce Security
  • Website Malware Infections
  • WordPress Security

WordPress Malware Collects Sensitive WooCommerce Data

  • Luke Leal
  • May 15, 2020
During a recent investigation, our team found malicious code that reveals how attackers are performing reconnaissance to identify if sites are actively using WooCommerce in…
Read the Post
Labs Note
  • Sucuri Labs
  • Vulnerability Disclosure
  • WordPress Security

Unauthenticated Stored Cross Site Scripting in WP Product Review

  • John Castro
  • May 14, 2020
During a routine research audit for our Sucuri Firewall, we discovered an Unauthenticated Persistent Cross-Site Scripting (XSS) affecting 40,000+ users of the WP Product Review…
Read the Post
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • Website Security
  • WordPress Security

WordPress Admin Login Stealer

  • Krasimir Konov
  • April 27, 2020
During an investigation, we identified a WordPress login stealer using the PHP functions curl and file_get_contents. The malicious code was injected into the core file…
Read the Post
Duplicated WordPress Vulnerabilities
  • Website Security
  • WordPress Security

Duplicated Vulnerabilities in WordPress Plugins

  • Antony Garand
  • April 24, 2020
During a recent plugin audit, we noticed a weird pattern among many plugins responsible for performing a specific task: Duplicating a page or a post.…
Read the Post
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • Website Security
  • WordPress Security

Fake M-Shield WordPress Plugin

  • Krasimir Konov
  • April 21, 2020
During a recent malware investigation, we found a fake WordPress plugin called M-Shield. We also found almost an identical plugin under the name kingof, with…
Read the Post
WordPress Redirect Hack via Test0.com/Default7.com
  • Website Malware Infections
  • Website Security
  • WordPress Security

Obfuscated WordPress Malware Dropper

  • Luke Leal
  • April 21, 2020
It goes without saying that evasive maneuvering is at the top of a hacker’s priority list. Most often, they try to evade detection by obfuscating…
Read the Post
  • Vulnerability Disclosure
  • Website Malware Infections
  • Website Security
  • WordPress Security

OneTone Vulnerability Leads to JavaScript Cookie Hijacking

  • Luke Leal
  • April 15, 2020
A vulnerability in the discontinued WordPress theme OneTone has been added to an ongoing campaign that is targeting vulnerable WordPress websites and causes malicious redirects…
Read the Post
WordPress Continues to Fall Victim to Carding Attacks
  • Ecommerce Security
  • Website Security
  • WordPress Security

Analysis of a WordPress Credit Card Swiper

  • Ben Martin
  • April 9, 2020
While working on a recent case, I found something on a WordPress website that is not as common as on Magento environments: A credit card…
Read the Post
Search
Sucuri Sidebar Malware Removal to Signup Page
Sucuri Logo

Let’s Connect

Products
Website Firewall Website Security Platform WordPress Security Website Backups Hack Assistance Pricing
Solutions
DDoS Protection Malware Detection Malware Removal Malware Prevention Blacklist Removal SEO Spam Removal
USE CASES
Developers Ecommerce Agency Plans Enterprise Services HTTPS/2 Virtual Patching
Support
Knowledge Base SiteCheck Guides Research Labs Report Abuse Status Report
Company
About Sucuri Contact Blog Referral Partners Testimonials
Terms of Use Privacy Policy Do Not Sell My Personal Information Frequently Asked Questions

© 2025 GoDaddy Mediatemple, Inc., d/b/a Sucuri. All rights reserved.

back to top

'