Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
  • Immediate Help
Login
Login

New Customer?

Sign up now.
  • Submit a ticket
  • Knowledge base
  • Chat now

Browsing Category

WordPress Security

662 posts
  • Security Advisory
  • Vulnerability Disclosure
  • WordPress Security

Security Advisory: Stored XSS in bbPress

  • Marc-Alexandre Montpas
  • May 3, 2016
During regular research audits of our Sucuri Firewall, we discovered a Stored XSS vulnerability affecting the bbPress plugin for WordPress which is currently installed on…
Read the Post
  • Security Advisory
  • Website Security
  • WordPress Security

Beware of Unverified TLS Certificates in PHP & Python

  • Peter Kankowski
  • March 31, 2016
Web developers today rely on various third-party APIs. For example, these APIs allow you to accept credit card payments, integrate a social network with your…
Read the Post
  • Security Education
  • Website Security
  • WordPress Security

Ask Sucuri: How Does Sucuri Clean a Website?

  • Daniel Cid
  • March 23, 2016
Question: How does Sucuri clean hacked websites? What is the process? We clean a lot of websites, ~ 400 / 500, daily during our normal load. To…
Read the Post
  • Website Malware Infections
  • WordPress Security

When a WordPress Plugin Goes Bad

  • Denis Sinegubko
  • March 4, 2016
Update March 7: The WordPress Directory team investigated and mitigated this issue by disconnecting the wooranker account from all plugins, reverting malicious changes in the…
Read the Post
Revslider new vulnerability with IRC Botnet
  • Security Education
  • Website Malware Infections
  • WordPress Security

Behind the Malware – Botnet Analysis

  • Antony Garand
  • February 24, 2016
While analyzing our website firewall logs we discovered an old vulnerability being retargeted in RevSlider, a popular WordPress plugin. In 2014 / 2015, this led to massive website compromises.…
Read the Post
  • Security Education
  • Website Malware Infections
  • WordPress Security

WordPress Sites Leveraged in Layer 7 DDoS Campaigns

  • Daniel Cid
  • February 17, 2016
We first disclosed that the WordPress pingback method was being misused to perform massive layer 7 Distributed Denial of Service (DDoS) attacks back in March 2014. The…
Read the Post
Seo-Moz Website Spam
  • WordPress Security

Seo-moz.com SEO Spam Campaign

  • Bruno Zanelato
  • February 10, 2016
Here at Sucuri we handle countless cases of SEO spam. This malware involves a website being compromised in order to spread (mostly pharmaceutical) advertisements by…
Read the Post
  • Sucuri Updates
  • WordPress Security

Server Security: Import WordPress Events to OSSEC

  • Daniel Cid
  • February 3, 2016
We leverage OSSEC extensively to help monitor and protect our servers. If you are not familiar with OSSEC, it is an open source Intrusion Detection System…
Read the Post
  • Website Security
  • WordPress Security

Massive Admedia/Adverting iFrame Infection

  • Denis Sinegubko
  • February 1, 2016
This past weekend we registered a spike in WordPress infections where hackers injected encrypted code at the end of all legitimate .js files. The distinguishing…
Read the Post
  • Magento Security
  • Website Security
  • WordPress Security

Malicious Pastebin Replacement for jQuery

  • Denis Sinegubko
  • January 6, 2016
Website hackers are always changing tactics and borrowing ideas from each other. One of the challenges of website security is staying on top of those…
Read the Post
Using WP Scan
  • Security Education
  • Vulnerability Disclosure
  • WordPress Security

Using WPScan: Finding WordPress Vulnerabilities

  • Alycia Mitchell
  • December 23, 2015
When using WPScan you can scan your WordPress website for known vulnerabilities within the core version, plugins, and themes. You can also find out if…
Read the Post
Search
Sucuri Sidebar Malware Removal to Signup Page
Sucuri Logo

Let’s Connect

Products
Website Firewall Website Security Platform WordPress Security Website Backups Hack Assistance Pricing
Solutions
DDoS Protection Malware Detection Malware Removal Malware Prevention Blacklist Removal SEO Spam Removal
USE CASES
Developers Ecommerce Agency Plans Enterprise Services HTTPS/2 Virtual Patching
Support
Knowledge Base SiteCheck Guides Research Labs Report Abuse Status Report
Company
About Sucuri Contact Blog Referral Partners Testimonials
Terms of Use Privacy Policy Do Not Sell My Personal Information Frequently Asked Questions

© 2025 GoDaddy Mediatemple, Inc., d/b/a Sucuri. All rights reserved.

back to top

'