Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
  • Immediate Help
Login
Login

New Customer?

Sign up now.
  • Submit a ticket
  • Knowledge base
  • Chat now

Browsing Category

WordPress Security

652 posts
Unwanted Popups Caused By Plugins
  • Website Security
  • WordPress Security

Unwanted Pop-ups Caused by Injectbody/Injectscr Plugins

  • Denis Sinegubko
  • February 12, 2018
On February 8th, 2018, we noticed a new wave of WordPress infections involving two malicious plugins: injectbody and injectscr. These plugins inject obfuscated scripts, creating…
Read the Post
WordPress Vulnerablity Disclosre
  • Ecommerce Security
  • Vulnerability Disclosure
  • WordPress Security

SQLi Vulnerability in YITH WooCommerce Wishlist

  • John Castro
  • January 16, 2018
As part of our regular research audits for our Sucuri Firewall, we discovered an SQL Injection vulnerability affecting the YITH WooCommerce Wishlist plugin for WordPress.…
Read the Post
Malicious cryptominers from GitHub
  • Website Malware Infections
  • WordPress Security

Malicious Website Cryptominers from GitHub. Part 2.

  • Denis Sinegubko
  • January 3, 2018
Recently we wrote about how GitHub/GitHub.io was used in attacks that injected cryptocurrency miners into compromised websites. Around the same time, we noticed another attack…
Read the Post
  • Website Malware Infections
  • WordPress Security

Reverse Javascript Injection Redirects to Support Scam on WordPress

  • Ben Martin
  • December 21, 2017
Over the last few weeks, we’ve noticed a JavaScript injection in a number of WordPress databases, and we recently wrote about them in a Sucuri…
Read the Post
Javascript Injection Creates Rogue WordPress User
  • WordPress Security

Javascript Injection Creates Rogue WordPress Admin User

  • Douglas Santos
  • December 14, 2017
Earlier this year, we faced a growing volume of infections related to a vulnerability in outdated versions of the Newspaper and Newsmag themes. The infection…
Read the Post
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

Reversed URLs Randomly Redirect to Scams

  • Denis Sinegubko
  • December 14, 2017
We are seeing hundreds of infected WordPress sites with the following scripts (in one line) injected in random places in wp_posts table. $vTB$I_919AeEAw2z$KX=function(n){if (typeof ($vTB$I_919AeEAw2z$KX.list[n])…
Read the Post
  • Website Malware Infections
  • WordPress Security

Malicious Cryptominers from GitHub

  • Denis Sinegubko
  • December 7, 2017
Recently, a webmaster contacted us when his AVG antivirus reported that the JS:Miner-C [Trj] infection was found on their site. Our investigation revealed a hidden…
Read the Post
  • Website Malware Infections
  • WordPress Security

Cloudflare[.]Solutions Keylogger on Thousands of Infected WordPress Sites

  • Denis Sinegubko
  • December 6, 2017
Update Dec. 8 2017: The cloudflare[.]solutions domain has now been taken down. A few weeks ago, we wrote about a massive WordPress infection that injected an…
Read the Post
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

WP-VCD Malware Comes with Nulled Themes

  • Denis Sinegubko
  • December 6, 2017
Recently we wrote about wp-vcd malware that created rogue WordPress admin users (100010010) and injected spam links. Our readers noticed that the “nulled” premium theme…
Read the Post
Formidable Forms & Shortcodes Exploits
  • Security Advisory
  • Website Security
  • WordPress Security

Formidable Forms / Shortcodes Ultimate Exploits In The Wild

  • Marc-Alexandre Montpas
  • November 24, 2017
On Monday, November 20th, we were notified about a vulnerability that poses a serious security risk when the Shortcodes Ultimate and Formidable Forms plugins are…
Read the Post
WordPress Vulnerablity Disclosre
  • Vulnerability Disclosure
  • WordPress Security

SQL Injection in bbPress

  • Marc-Alexandre Montpas
  • November 13, 2017
During regular audits of our Sucuri Firewall (WAF), one of our researchers at the time, Slavco Mihajloski, discovered an SQL Injection vulnerability affecting bbPress. If…
Read the Post
Search
What is SQL injection and how to prevent attacks sidebar
Sucuri Sidebar Malware Removal to Signup Page
Sucuri Logo

Let’s Connect

Products
Website Firewall Website Security Platform WordPress Security Website Backups Hack Assistance Pricing
Solutions
DDoS Protection Malware Detection Malware Removal Malware Prevention Blacklist Removal SEO Spam Removal
USE CASES
Developers Ecommerce Agency Plans Enterprise Services HTTPS/2 Virtual Patching
Support
Knowledge Base SiteCheck Guides Research Labs Report Abuse Status Report
Company
About Sucuri Contact Blog Referral Partners Testimonials
Terms of Use Privacy Policy Do Not Sell My Personal Information Frequently Asked Questions

© 2025 GoDaddy Mediatemple, Inc., d/b/a Sucuri. All rights reserved.

back to top

'