Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
  • Immediate Help
Login
Login

New Customer?

Sign up now.
  • Submit a ticket
  • Knowledge base
  • Chat now

Browsing Category

WordPress Security

669 posts
WordPress Vulnerability Detail
  • Vulnerability Disclosure
  • WordPress Security

Stored XSS Patched in WordPress 5.1.1

  • Marc-Alexandre Montpas
  • March 26, 2019
WordPress recently released an update, 5.1.1, which patches a stored XSS vulnerability in the platform’s comment system. Even 10 days after the release of this…
Read the Post
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

Super Amazon Banners Plugin Gone Rogue

  • Krasimir Konov
  • March 26, 2019
During a recent investigation we found the plugin Super Amazon Banners to be serving malware/spam via the domain seoranker[.]info. We suspect that the domain expired…
Read the Post
Labs Note
  • Sucuri Labs
  • Vulnerability Disclosure
  • Website Malware Infections
  • WordPress Security

Multi-Vector Attack in Server Logs

  • John Castro
  • March 25, 2019
We recently noticed an increase on suspicious requests in our logs which reveal a planned attack against the Social Warfare plugin. Bad actors added this…
Read the Post
Stored XSS in MyBB
  • Vulnerability Disclosure
  • WordPress Security

Zero-Day Stored XSS in Social Warfare

  • Marc-Alexandre Montpas
  • March 21, 2019
A zero-day vulnerability has just appeared in the WordPress plugin world, affecting over 70,000 sites using the Social Warfare plugin. The plugin is vulnerable to…
Read the Post
WordPress Vulnerability Detail
  • Vulnerability Disclosure
  • WordPress Security

0day Vulnerability in Easy WP SMTP Affects Thousands of Sites

  • Marc-Alexandre Montpas
  • March 21, 2019
The Easy WP SMTP plugin authors have released a new update, fixing a very critical 0day vulnerability. When leveraged, this vulnerability gives unauthenticated attackers the…
Read the Post
Arbitrary Directory Deletion in WP-Fastest-Cache
  • Vulnerability Disclosure
  • Website Security
  • WordPress Security

Arbitrary Directory Deletion in WP-Fastest-Cache

  • Marc-Alexandre Montpas
  • March 18, 2019
The WP-Fastest-Cache plugin authors released a new update, version 0.8.9.1, fixing a vulnerability (CVE-2019-6726) present during its install alongside the WP-PostRatings plugin. According to seclists.org:…
Read the Post
Stored XSS in MyBB
  • Vulnerability Disclosure
  • WordPress Security

Insufficient Privilege Validation in SiteGround Optimizer & Caldera Forms Pro

  • Marc-Alexandre Montpas
  • March 13, 2019
While investigating the SiteGround Optimizer and Caldera Forms Pro plugins we have discovered a critical privilege escalation vulnerability. It was not being abused externally and…
Read the Post
How to add SSL and Move WordPress from HTTP to HTTPS
  • Security Education
  • Sucuri
  • Website Security
  • WordPress Security

How to Add SSL & Move WordPress from HTTP to HTTPS

  • Juliana Lewis
  • March 6, 2019
Moving a WordPress website from HTTP to HTTPS should be a priority for any webmaster. Recent statistics show that over 33% of website administrators across…
Read the Post
Fake Browser Updates Push Ransomware and Bank Malware
  • Website Malware Infections
  • Website Security
  • WordPress Security

Fake Browser Updates Push Ransomware and Bank Malware

  • Denis Sinegubko
  • February 28, 2019
Recently we came across a malicious campaign injecting scripts that push fake browser updates onto site visitors. This is what a typical fake update request…
Read the Post
The Importance of Website Logs
  • Security Advisory
  • Security Education
  • Website Security
  • WordPress Security

The Importance of Website Logs

  • Krasimir Konov
  • February 19, 2019
As a security company, we deal with a lot of compromised websites. Unfortunately, in most cases, we have limited access to customer logs, which is…
Read the Post
Spam Injector Disguised as a License Key in a WordPress Website
  • Website Malware Infections
  • Website Security
  • WordPress Security

Spam Injector Disguised as License Key in WordPress Website

  • Moe O
  • January 29, 2019
Here at Sucuri, we clean WordPress websites every day. There are various types of common malware, but when we stumble upon a different scenario, our…
Read the Post
Search
Sucuri Sidebar Malware Removal to Signup Page
Sucuri Logo

Let’s Connect

Products
Website Firewall Website Security Platform WordPress Security Website Backups Hack Assistance Pricing
Solutions
DDoS Protection Malware Detection Malware Removal Malware Prevention Blacklist Removal SEO Spam Removal
USE CASES
Developers Ecommerce Agency Plans Enterprise Services HTTPS/2 Virtual Patching
Support
Knowledge Base SiteCheck Guides Research Labs Report Abuse Status Report
Company
About Sucuri Contact Blog Referral Partners Testimonials
Terms of Use Privacy Policy Do Not Sell My Personal Information Frequently Asked Questions

© 2025 GoDaddy Mediatemple, Inc., d/b/a Sucuri. All rights reserved.

back to top

'