Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
  • Immediate Help
Login
Login

New Customer?

Sign up now.
  • Submit a ticket
  • Knowledge base
  • Chat now

Browsing Category

WordPress Security

674 posts
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

Plugins added to Malware Campaign: November 2019

  • John Castro
  • December 2, 2019
This is an update for the long-lasting malware campaign targeting vulnerable plugins since January. Please check our previous updates below: Multi-Vector Attack in Server Logs:…
Read the Post
  • Security Education
  • Website Security
  • WordPress Security

Another Fake Google Domain: fonts.googlesapi.com

  • Luke Leal
  • December 2, 2019
Our Remediation team lead Ben Martin recently found a fake Google domain that is pretty convincing to the naked eye. The malicious domain was abusing…
Read the Post
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

Wrong content-type to XSS

  • John Castro
  • November 22, 2019
WordPress Social Sharing Plugin – Sassy Social Share, which currently has over 100000 installations just fixed a Cross Site Scripting Vulnerability. This bug allows attackers…
Read the Post
Vulnerable Versions of Adminer as a Universal Infection Vector
  • Magento Security
  • Sucuri
  • Website Malware Infections
  • Website Security
  • WordPress Security

Vulnerable Versions of Adminer as a Universal Infection Vector

  • Denis Sinegubko
  • November 9, 2019
This past week, we’ve been monitoring a new wave of website infections mostly impacting WordPress and Magento websites. We found that hackers have been injecting…
Read the Post
  • Ecommerce Security
  • Magento Security
  • WordPress Security

Skimmers for Both Magento and WordPress

  • Denis Sinegubko
  • November 7, 2019
We often write about malware that steal payment information from sites built with Magento and other types of e-commerce CMS. When discussing credit card skimmers…
Read the Post
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

Plugins added to Malware Campaign: October 2019

  • John Castro
  • November 6, 2019
This is an update for the long-lasting malware campaign targeting vulnerable plugins during August and September. Please check our previous updates below: Multi-Vector Attack in…
Read the Post
  • Website Malware Infections
  • Website Security
  • WordPress Security

Pharma Spam Redirects to .su & .eu Sites

  • Denis Sinegubko
  • November 4, 2019
We regularly clean all sorts of black hat SEO infections. During these infection cleanups, we often find compromised websites redirecting visitors to fake “Canadian Pharmacy”…
Read the Post
HTML entity encoding in WordPress malware
  • Website Security
  • WordPress Security

Data URLs and HTML Entities in New WordPress Malware

  • Denis Sinegubko
  • October 30, 2019
Last week, an ongoing WordPress malware campaign started a new wave which included a variety of experimental injection types. Scripts as Data URLs The first…
Read the Post
Fake UpdraftPlus WordPress Plugin
  • Website Security
  • WordPress Security

Fake UpdraftPlus Plugins

  • Denis Sinegubko
  • October 17, 2019
We often find various fake WordPress plugins installed by hackers during website cleanups. Recently, we’ve noticed a new wave of infections that install fake plugins…
Read the Post
Backdoors in Malicious Plugins
  • Website Security
  • WordPress Security

Cryptominers & Backdoors Found in Fake Plugins

  • Krasimir Konov
  • October 16, 2019
When cleaning websites, we regularly find phishing pages, malicious code injected into files, and SEO spam. However, over the past couple of months we’ve also…
Read the Post
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

Plugins added to Malware Campaign: September 2019

  • John Castro
  • October 3, 2019
This is an update for the long-lasting malware campaign targeting vulnerable plugins during August and September. Please check our previous updates below: Multi-Vector Attack in…
Read the Post
Search
Sucuri Sidebar Malware Removal to Signup Page
Sucuri Logo

Let’s Connect

Products
Website Firewall Website Security Platform WordPress Security Website Backups Hack Assistance Pricing
Solutions
DDoS Protection Malware Detection Malware Removal Malware Prevention Blacklist Removal SEO Spam Removal
USE CASES
Developers Ecommerce Agency Plans Enterprise Services HTTPS/2 Virtual Patching
Support
Knowledge Base SiteCheck Guides Research Labs Report Abuse Status Report
Company
About Sucuri Contact Blog Referral Partners Testimonials
Terms of Use Privacy Policy Do Not Sell My Personal Information Frequently Asked Questions

© 2025 GoDaddy Mediatemple, Inc., d/b/a Sucuri. All rights reserved.

back to top

'