Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
  • Immediate Help
Login
Login

New Customer?

Sign up now.
  • Submit a ticket
  • Knowledge base
  • Chat now

Browsing Category

WordPress Security

669 posts
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

Malware Campaign Evolves to Target New Plugins: May 2019

  • John Castro
  • May 28, 2019
A long-lasting malware campaign targeting deprecated, vulnerable versions of plugins continues to be leveraged by attackers to inject malicious scripts into affected websites. Easily automated…
Read the Post
Return to the City of Cron - Malware Infections on Joomla and WordPress
  • Joomla Security
  • Website Security
  • WordPress Security

Return to the City of Cron – Malware Infections on Joomla and WordPress

  • Luke Leal
  • May 27, 2019
We recently had a client that had a persistent malware infection on their shared hosting environment that would re-infect the files quickly after we had…
Read the Post
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

Threat intelligence gathering from slight changes in malicious code samples

  • Luke Leal
  • May 24, 2019
We found the following PHP backdoor in August 2018 along with other malware samples uploaded after hackers exploit a specific vulnerable WordPress plugin covered in…
Read the Post
.Htaccess Injector on Joomla and WordPress Websites
  • Joomla Security
  • Website Security
  • WordPress Security

.htaccess Injector on Joomla and WordPress Websites

  • Eugene Wozniak
  • May 23, 2019
During the process of investigating one of our incident response cases, we found an .htaccess code injection. It had been widely spread on the website,…
Read the Post
WordPress Vulnerability
  • Vulnerability Disclosure
  • Website Security
  • WordPress Security

Slimstat: Stored XSS from Visitors

  • Antony Garand
  • May 21, 2019
The WordPress Slimstat plugin, which currently has over 100k installs, allows your website to gather analytics data for your WordPress website. It will track certain…
Read the Post
WordPress Vulnerability
  • Vulnerability Disclosure
  • Website Security
  • WordPress Security

Persistent Cross-site Scripting in WP Live Chat Support Plugin

  • John Castro
  • May 15, 2019
During a routine research audits for our Sucuri Firewall, we discovered an Unauthenticated Persistent Cross-Site Scripting (XSS) affecting 60,000+ users of the  WP Live Chat…
Read the Post
WordPress Vulnerability
  • Vulnerability Disclosure
  • Website Security
  • WordPress Security

WordPress Plugin Give – Stored XSS for Donors

  • Antony Garand
  • May 15, 2019
​​Give is a WordPress plugin which allows users to setup a donation page on a website. It currently has 60k installs. ​​During a recent audit…
Read the Post
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

array_diff_ukey Usage in Malware Obfuscation

  • Luke Leal
  • May 14, 2019
We discovered a PHP backdoor on a WordPress installation that contained some interesting obfuscation methods to keep it hidden from prying eyes: $zz1 = chr(95).chr(100).chr(101).chr(115).chr(116).chr(105).chr(110).chr(97).chr(116).chr(105).chr(111).chr(110);…
Read the Post
WordPress Vulnerability
  • Vulnerability Disclosure
  • Website Security
  • WordPress Security

Multiple Vulnerabilities in the WordPress Ultimate Member Plugin

  • Antony Garand
  • May 13, 2019
The Ultimate member plugin version 2.0.45 and lower is affected by multiple vulnerabilities, among them is a critical vulnerability allowing malicious users to read and…
Read the Post
WordPress Vulnerability Detail
  • Vulnerability Disclosure
  • WordPress Security

Persistent XSS via CSRF in WP Meta and Date Remover

  • John Castro
  • May 7, 2019
During regular research audits for our Sucuri Firewall (WAF), we discovered a Cross Site Request Forgery (CSRF) leading to a persistent Cross Site Scripting vulnerability…
Read the Post
WordPress Vulnerability Detail
  • Vulnerability Disclosure
  • WordPress Security

Insufficient Privilege Validation in WooCommerce Checkout Manager

  • John Castro
  • April 29, 2019
Due to the poor handling of a vulnerability disclosure, a new attack vector has appeared for the WooCommerce Checkout Manager WordPress plugin and is affecting…
Read the Post
Search
Sucuri Sidebar Malware Removal to Signup Page
Sucuri Logo

Let’s Connect

Products
Website Firewall Website Security Platform WordPress Security Website Backups Hack Assistance Pricing
Solutions
DDoS Protection Malware Detection Malware Removal Malware Prevention Blacklist Removal SEO Spam Removal
USE CASES
Developers Ecommerce Agency Plans Enterprise Services HTTPS/2 Virtual Patching
Support
Knowledge Base SiteCheck Guides Research Labs Report Abuse Status Report
Company
About Sucuri Contact Blog Referral Partners Testimonials
Terms of Use Privacy Policy Do Not Sell My Personal Information Frequently Asked Questions

© 2025 GoDaddy Mediatemple, Inc., d/b/a Sucuri. All rights reserved.

back to top

'