Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
  • Immediate Help
Login
Login

New Customer?

Sign up now.
  • Submit a ticket
  • Knowledge base
  • Chat now

Browsing Category

WordPress Security

662 posts

Critical Vulnerability Disclosed on WordPress Custom Contact Forms Plugin

  • Marc-Alexandre Montpas
  • August 7, 2014
If you’re a using the Custom Contact Forms WordPress plugin, you need to update it right away. During a routine audit for our WAF, we…
Read the Post

WordPress and Drupal Core Denial Of Service Vulnerability – Moderately Critical

  • David Dede
  • August 6, 2014
Both WordPress and Drupal are affected by a DoS (denial of service) vulnerability on the PHP XML parser used by their XMLRPC implementations. The issue…
Read the Post

New Brute Force Attacks Exploiting XMLRPC in WordPress

  • Daniel Cid
  • July 24, 2014
Brute force attacks against WordPress have always been very common. In fact, Brute Force attacks against any CMS these days is a common occurrence, what…
Read the Post

MailPoet Vulnerability Exploited in the Wild – Breaking Thousands of WordPress Sites

  • Daniel Cid
  • July 23, 2014
A few weeks ago we found and disclosed a serious vulnerability on the MailPoet WordPress Plugin. We urged everyone to upgrade their sites immediately due…
Read the Post

Massive Malware Infection Breaking WordPress Sites

  • Peter Gramantik
  • July 22, 2014
Update: We identified the root cause: MailPoet Vulnerability Exploited in the Wild – Breaking Thousands of WordPress Sites. The last few days has brought about…
Read the Post

Disclosure: Insecure Nonce Generation in WPtouch

  • Marc-Alexandre Montpas
  • July 14, 2014
If you use the popular WPtouch plugin (5M+ downloads) on your WordPress website, you should update it immediately. During a routine audit for our WAF,…
Read the Post

Ask Sucuri: Who is Logging into My WordPress Site?

  • Daniel Cid
  • July 3, 2014
Today, we’re going to revisit our Q&A series. If you have any questions about malware, blacklisting, or security in general, send them to us at:…
Read the Post

Remote File Upload Vulnerability in WordPress MailPoet Plugin (wysija-newsletters)

  • Daniel Cid
  • July 1, 2014
Marc-Alexandre Montpas, from our research team, found a serious security vulnerability in the MailPoet WordPress plugin. This bug allows an attacker to upload any file…
Read the Post

TimThumb WebShot Code Execution Exploit (Zeroday)

  • Daniel Cid
  • June 25, 2014
If you are still using Timthumb after the serious vulnerability that was found on it last year, you have one more reason to be concerned.…
Read the Post

Spam Hack Targets WordPress Core Install Directories

  • Daniel Cid
  • June 24, 2014
Do you run your website on WordPress? Have you checked the integrity of your core install lately for SPAM like “Google Pharmacy” stores or other…
Read the Post

WordPress Plugin Alert – LoginWall Imposter Exposed

  • Rafael Capovilla
  • June 10, 2014
When you work with malware for a while, you start to become very good at pattern recognition. A couple sites in every hundred cleaned might…
Read the Post
Search
Sucuri Sidebar Malware Removal to Signup Page
Sucuri Logo

Let’s Connect

Products
Website Firewall Website Security Platform WordPress Security Website Backups Hack Assistance Pricing
Solutions
DDoS Protection Malware Detection Malware Removal Malware Prevention Blacklist Removal SEO Spam Removal
USE CASES
Developers Ecommerce Agency Plans Enterprise Services HTTPS/2 Virtual Patching
Support
Knowledge Base SiteCheck Guides Research Labs Report Abuse Status Report
Company
About Sucuri Contact Blog Referral Partners Testimonials
Terms of Use Privacy Policy Do Not Sell My Personal Information Frequently Asked Questions

© 2025 GoDaddy Mediatemple, Inc., d/b/a Sucuri. All rights reserved.

back to top

'