Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
  • Immediate Help
Login
Login

New Customer?

Sign up now.
  • Submit a ticket
  • Knowledge base
  • Chat now

Browsing Category

WordPress Security

669 posts
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

Spam Injector Disguised as a License Key

  • Moe O
  • January 7, 2019
A client reported some weird spam URLs injected on their WordPress website and after an investigation, it turned out that the hacker was hiding the…
Read the Post
Personal Security Best Practices
  • Security Advisory
  • Security Education
  • WordPress Security

OWASP Top 10 Security Risks – Part III

  • Gerson Ruiz
  • December 11, 2018
To bring awareness to what threatens the integrity of websites, we are continuing a series of posts on the OWASP top 10 security risks. The…
Read the Post
Using Innocent Roles to Hide Admin Users
  • Security Education
  • WordPress Security

Using Innocent Roles to Hide Admin Users

  • Cesar Anjos
  • December 4, 2018
All across the internet, we find guides and tutorials on how to keep your WordPress site secure. Most of them approach the concept of user…
Read the Post
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

Side Effects of the Site_url Hack

  • Denis Sinegubko
  • November 20, 2018
We\’ve been cleaning many sites infected by the so-called site_url hack–the result of the WP GDPR Compliance plugin vulnerability. The sites are broken because their…
Read the Post
Massive GDPR Infection Pastebin
  • Website Security
  • WordPress Security

Hackers Change WordPress Siteurl to Pastebin

  • Denis Sinegubko
  • November 13, 2018
Last Friday, we reported on a hack that used a vulnerability in the popular WP GDPR Compliance plugin to change WordPress siteurl settings to erealitatea[.]net.…
Read the Post
Fake UpdraftPlus WordPress Plugin
  • WordPress Security

Erealitatea[.]net Hack Corrupts Websites with WP GDPR Compliance Plugin Vulnerability

  • Pedro Peixoto
  • November 9, 2018
We have noticed a growing number of WordPress-based sites that have had their URL settings changed to hxxp://erealitatea[.]net. Further investigations show that the issue is…
Read the Post
  • Security Education
  • Web Pros
  • WordPress Security

New WordPress Security Email Course

  • Rianna MacLeod
  • November 5, 2018
Recent statistics show that over 32% of website administrators across the web use WordPress. Unfortunately, the CMSs popularity comes at a price — attackers often…
Read the Post
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

Fake Wp.org/jquery.js

  • Denis Sinegubko
  • October 30, 2018
There is a long-lasting malware campaign (dating back to at least 2016) that injects fake jQuery scripts: <script type=”text/javascript” src=”hxxps://www.XX[X]wp[.]org/jquery.js”></script> Where XX[X] are 2 or…
Read the Post
Saskmade Redirects
  • WordPress Security

Saskmade[.]net Redirects

  • Denis Sinegubko
  • October 26, 2018
Earlier this week, we published a blog post about an ongoing massive malware campaign describing multiple infection vectors that it uses. This same week, we…
Read the Post
Multiple Ways to Inject Tech Support Scams
  • WordPress Security

Multiple Ways to Inject the Same Tech Support Scam Malware

  • Denis Sinegubko
  • October 23, 2018
Last month, we shared information about yet another series of ongoing massive infections using multiple different vectors to inject malicious scripts into WordPress websites. Shortly…
Read the Post
Backdoor using a paste site to host payload
  • Website Malware Infections
  • Website Security
  • WordPress Security

Backdoor Uses Paste Site to Host Payload

  • Bruno Zanelato
  • September 18, 2018
Finding backdoors is one of the biggest challenges of a website security analyst, as backdoors are designed to be hidden in case the malware is found…
Read the Post
Search
Sucuri Sidebar Malware Removal to Signup Page
Sucuri Logo

Let’s Connect

Products
Website Firewall Website Security Platform WordPress Security Website Backups Hack Assistance Pricing
Solutions
DDoS Protection Malware Detection Malware Removal Malware Prevention Blacklist Removal SEO Spam Removal
USE CASES
Developers Ecommerce Agency Plans Enterprise Services HTTPS/2 Virtual Patching
Support
Knowledge Base SiteCheck Guides Research Labs Report Abuse Status Report
Company
About Sucuri Contact Blog Referral Partners Testimonials
Terms of Use Privacy Policy Do Not Sell My Personal Information Frequently Asked Questions

© 2025 GoDaddy Mediatemple, Inc., d/b/a Sucuri. All rights reserved.

back to top

'