WordPress Security & Threat Intelligence
Your source for WordPress security news today. Browse our live archive of active vulnerabilities, bypass URL exploits, and zero-day malware signatures detected in the wild.
Malware Analysis of StateMesh in WordPress MU-Plugin Directory
Type: Malware
Hidden WordPress Plugin: WP Security Helper
Type: Malware
Hidden Casino Content Injection
Type: Content Injection
Malicious PHP Code Injection in WordPress Directories
Type: Malware
Japanese SEO Spam Injection via Malicious PHP Code
Type: Malware
Malicious PHP Script Detected in index.php
Type: Malware
Fake Plugin - Advanced LinkFlow Control
Type: Stealth Backdoor / Fake Plugin
PHP Malware in index.php
Type: PHP Malware
Admin Backdoor User Creation
Type: WordPress Exploit
JavaScript Obfuscation Causing AJAX Malfunction
Type: Malware
Obfuscated JavaScript Malware in Theme Plugins
Type: Obfuscated JavaScript Malware
WordPress Backdoor Exploit
Type: Malware
Investigation into Malicious WordPress Core Plugin
Type: Malware
Malicious Redirection via _posts Table Injection
Type: Redirection
SavvyWolf Web Shell - Manager Variant
Type: PHP Backdoor / Web Shell
Hello Aili Plugin Spam Injector
Type: Spam Injection
Goto Obfuscated Dropper
Type: Backdoor
PHP Shell Ultimate Backdoor
Type: Backdoor
Malicious .htaccess Injection and Fake Index.php Dropper
Type: Access Control Malware and Backdoor
Recursive .htaccess PHP Execution Lockout
Type: Configuration Hijacking / Denial of Service
Cookie-Based PHP Execution Malware
Type: PHP Backdoor
Header-Based Backdoor Malware
Type: Backdoor
XOR-Obfuscated PHP Dropper
Type: Remote Code Execution (RCE) Backdoor
Drive-By Script Injection
Type: Script Injection
Fetch-Based URL Injection
Type: URL Injection
Hidden Plugin Backdoor
Type: Backdoor
Obfuscated JavaScript Credit Card Stealer
Type: Data Theft
JavaScript Fetch-Based Spam Injection
Type: JS Injection
JavaScript Redirection Injection
Type: Redirection Malware
Malicious Redirect via Hidden Plugin
Type: Malware, Backdoor
PHP Cron Job Malware
Type: Cron Malware
SEO Spam Malware Injection
Type: SEO Spam
WP Compatibility Patch Backdoor
Type: Backdoor