Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
  • Immediate Help
Login
Login

New Customer?

Sign up now.
  • Submit a ticket
  • Knowledge base
  • Chat now

Browsing Category

WordPress Security

672 posts
cryptominers on hacked sites blog header
  • Drupal Security
  • Joomla Security
  • Magento Security
  • Website Malware Infections
  • WordPress Security

Cryptominers on Hacked Sites – Part 2

  • Denis Sinegubko
  • October 25, 2017
Last month we wrote about how the emergence of website cryptocurrency miners resulted in hackers abusing the technology by injecting the CoinHive miners into compromised…
Read the Post
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

Attackers leveraging WP Maintenance plugin to deface websites

  • Bruno Zanelato
  • October 25, 2017
Recently, during a website investigation, we detected that attackers have been modifying the database structure of WP Maintenance plugin (which is a very popular wordpress…
Read the Post
x-wp-spam-shield-pro malicious fake plugin
  • WordPress Security

Fake Plugins, Fake Security

  • Peter Gramantik
  • September 28, 2017
Update: The plugin name is fake and has nothing to do with the well-known WP-SpamShield plugin in the official WordPress plugin repository. WordPress users are…
Read the Post
WordPress Vulnerablity Disclosre
  • Vulnerability Disclosure
  • WordPress Security

Stored Cross-Site Scripting Vulnerability in WordPress 4.8.1

  • Rodolfo Assis
  • September 26, 2017
Update 11/03/2017: Read all about vulnerabilities and best practices to secure your website in our newly WordPress Security Guide today! During regular research audits for…
Read the Post
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

Simple self updating hacktool

  • Pedro Peixoto
  • September 26, 2017
While working on a compromised website, it’s very common to encounter hacktools. Those are like the attackers’ swiss knife, allowing them to perform several tasks…
Read the Post
abandoned scripts and pitfalls of cleaning serialized data blog post header
  • Security Advisory
  • WordPress Security

Old Themes, Abandoned Scripts and Pitfalls of Cleaning Serialized Data

  • Denis Sinegubko
  • September 13, 2017
Over the summer, we’ve seen waves of WordPress database infections that use vulnerabilities in tagDiv’s Newspaper/Newsmag themes or InterconnectIT Search and Replace scripts (searchreplacedb2.php). The…
Read the Post
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

SEO spam loading from external site

  • Krasimir Konov
  • September 13, 2017
Many websites get compromised and used for SEO in order to drive traffic to other websites that would usually be ranked very low or completely…
Read the Post
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

Evil Self-Regenerating WordPress Administrator User

  • Andrey Kucherov
  • September 1, 2017
Attackers often aim to conceal their presence using different methods, such as injecting redirect scripts, creating spam pages, or hiding a mailer in checkout pages…
Read the Post
Expired Domain Leads To Plugin Redirect
  • Website Malware Infections
  • WordPress Security

Expired Domain Leads to WordPress Plugin Redirects

  • Krasimir Konov
  • August 24, 2017
A malicious redirect is a snippet of code used by attackers with the intention of redirecting visitors to another site; a very common tactic seen…
Read the Post
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

Small One-liner Backdoor

  • Samuel Odendaal
  • August 21, 2017
During an incident response investigation, we detected an interesting backdoor that was small but had the potential to give the attacker full access to your…
Read the Post
WordPress Vulnerablity Disclosre
  • Vulnerability Disclosure
  • WordPress Security

SQL Injection Vulnerability in WP Statistics

  • John Castro
  • June 30, 2017
Update 11/3/2017: We are always looking for the latest to be shared with you and now we have released our WordPress Security Guide, were you…
Read the Post
Search
What is SQL injection and how to prevent attacks sidebar
Sucuri Sidebar Malware Removal to Signup Page
Sucuri Logo

Let’s Connect

Products
Website Firewall Website Security Platform WordPress Security Website Backups Hack Assistance Pricing
Solutions
DDoS Protection Malware Detection Malware Removal Malware Prevention Blacklist Removal SEO Spam Removal
USE CASES
Developers Ecommerce Agency Plans Enterprise Services HTTPS/2 Virtual Patching
Support
Knowledge Base SiteCheck Guides Research Labs Report Abuse Status Report
Company
About Sucuri Contact Blog Referral Partners Testimonials
Terms of Use Privacy Policy Do Not Sell My Personal Information Frequently Asked Questions

© 2025 GoDaddy Mediatemple, Inc., d/b/a Sucuri. All rights reserved.

back to top

'