Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
  • Immediate Help
Login
Login

New Customer?

Sign up now.
  • Submit a ticket
  • Knowledge base
  • Chat now

Browsing Category

WordPress Security

672 posts
WordPress Vulnerablity Disclosre
  • WordPress Security

Stored XSS in WordPress Core

  • Marc-Alexandre Montpas
  • March 13, 2017
As you might remember, we recently blogged about a critical Content Injection Vulnerability in WordPress which allowed attackers to deface vulnerable websites. While our original disclosure only…
Read the Post
WordPress Vulnerablity Disclosre
  • Vulnerability Disclosure
  • WordPress Security

SQL Injection Vulnerability in NextGEN Gallery for WordPress

  • Slavco Mihajloski
  • February 27, 2017
As part of a vulnerability research project for our Sucuri Firewall (WAF), we have been auditing multiple open source projects looking for security issues. While…
Read the Post
  • Website Malware Infections
  • WordPress Security

WordPress Security – Fake TrafficAnalytics Website Infection

  • Rodrigo Escobar
  • February 17, 2017
Several months ago, our research team identified a fake analytics infection, known as RealStatistics. The malicious Javascript injection looks a lot like tracking code for…
Read the Post
  • Website Malware Infections
  • WordPress Security

RCE Attempts Against the Latest WordPress REST API Vulnerability

  • Daniel Cid
  • February 9, 2017
We are starting to see remote command execution (RCE) attempts trying to exploit the latest WordPress REST API Vulnerability. These RCE attempts started today after…
Read the Post
  • Website Malware Infections
  • WordPress Security

JavaScript Injections Leads to Tech Support Scam

  • Krasimir Konov
  • February 9, 2017
During a recent malware investigation, we found some interesting obfuscated Javascript code. This code pretends to appear as part of the popular AddThis social sharing…
Read the Post
  • Security Advisory
  • WordPress Security

WordPress REST API Vulnerability Abused in Defacement Campaigns

  • Daniel Cid
  • February 6, 2017
WordPress 4.7.2 was released two weeks ago, including a fix for a severe vulnerability in the WordPress REST API. We have been monitoring our WAF…
Read the Post
WordPress Vulnerablity Disclosre
  • Vulnerability Disclosure
  • WordPress Security

Content Injection Vulnerability in WordPress

  • Marc-Alexandre Montpas
  • February 1, 2017
As part of a vulnerability research project for our Sucuri Firewall (WAF), we have been auditing multiple open source projects looking for security issues. While…
Read the Post
  • Sucuri Updates
  • Web Pros
  • WordPress Security

Spotlight: Website Security Response for Photographers

  • Alycia Mitchell
  • January 27, 2017
It takes a lot of bravery to create a small business. Putting yourself out there and taking risks is not for the faint of heart.…
Read the Post
  • Website Malware Infections
  • WordPress Security

Fake bb_press Plugin Redirects to Mobile Pornography

  • Fernando Barbosa
  • January 24, 2017
When a website is hacked, we often find that attackers have injected multiple backdoors, web shells, and malicious code that allows them to regain access…
Read the Post
Labs Note
  • Sucuri Labs
  • Website Malware Infections
  • WordPress Security

Hooking WordPress Class to Hide Malicious Users

  • John Castro
  • January 20, 2017
When a website is compromised, attackers perform post-exploitation tasks to  maintain  access to the site for as long as possible. One of these actions is…
Read the Post
  • Drupal Security
  • Joomla Security
  • Magento Security
  • Security Education
  • Website Security
  • WordPress Security

Hacked Website Report – 2016/Q3

  • Daniel Cid
  • January 4, 2017
Today we are proud to release our quarterly Hacked Website Report for 2016/Q3. This report is based on data collected and analyzed by the Sucuri…
Read the Post
Search
Sucuri Sidebar Malware Removal to Signup Page
Sucuri Logo

Let’s Connect

Products
Website Firewall Website Security Platform WordPress Security Website Backups Hack Assistance Pricing
Solutions
DDoS Protection Malware Detection Malware Removal Malware Prevention Blacklist Removal SEO Spam Removal
USE CASES
Developers Ecommerce Agency Plans Enterprise Services HTTPS/2 Virtual Patching
Support
Knowledge Base SiteCheck Guides Research Labs Report Abuse Status Report
Company
About Sucuri Contact Blog Referral Partners Testimonials
Terms of Use Privacy Policy Do Not Sell My Personal Information Frequently Asked Questions

© 2025 GoDaddy Mediatemple, Inc., d/b/a Sucuri. All rights reserved.

back to top

'