WP•FIX Open incident
Home/Threat Library

WordPress Threat Library

Understand the threats behind hacked WordPress sites.

A growing technical library of WordPress malware, backdoors, redirects, SEO spam, WooCommerce attacks and recurring infection patterns.

High

Fake CAPTCHA Malware

Fake “verify you are human” overlays or pages that push malicious downloads, browser notifications or redirects.

Malware / Social EngineeringRead guide →
Critical

Balada Injector

A long-running WordPress malware campaign known for injected scripts, redirects, backdoors and reinfection.

Mass Malware CampaignRead guide →
High

WP-VCD Malware

A common malware family historically associated with nulled themes and plugins that creates persistence and reinfection.

Nulled Theme / BackdoorRead guide →
Medium

Japanese SEO Hack

Spam pages and Japanese search snippets injected into Google results through hacked WordPress files or database content.

SEO SpamRead guide →
High

WordPress Spam Redirect Malware

Visitors are redirected to scam, adult, gambling, pharma or malware sites through JavaScript, htaccess or PHP payloads.

RedirectsRead guide →
High

Fake Plugin Malware

Attackers hide malicious code inside a plugin that looks like a normal utility, cache module or system helper.

PersistenceRead guide →
Critical

WooCommerce Credit Card Skimmer

Malicious JavaScript injected into checkout pages to steal or intercept payment form data or customer trust.

WooCommerceRead guide →
High

Hidden WordPress Admin User

A rogue administrator account is created to maintain access after malware cleanup.

Account TakeoverRead guide →
Critical

wp-config.php Backdoor

Malicious PHP code is inserted into wp-config.php to load malware before WordPress fully starts.

BackdoorRead guide →
High

WordPress Cron Malware

Malware uses scheduled WordPress cron events to reinfect files, fetch payloads or recreate malicious users.

PersistenceRead guide →
High

.htaccess Redirect Malware

Malicious rewrite rules redirect visitors or search engines before WordPress handles the request.

RedirectsRead guide →
High

WordPress Database Malware

Malicious payloads are stored in wp_options, posts, widgets, menus or plugin settings instead of visible files.

Database InjectionRead guide →
Medium

Base64 / eval PHP Malware

Obfuscated PHP code uses base64_decode, eval, gzinflate or similar functions to hide malicious behavior.

Obfuscated PHPRead guide →
High

Elementor Malware

Malicious scripts or spam content injected through Elementor templates, widgets, custom code or related plugins.

Page Builder / PluginRead guide →
High

Nulled Theme Backdoor

Pirated themes often contain hidden backdoors, link injections, remote loaders and admin persistence.

Nulled SoftwareRead guide →
Critical

WordPress Phishing Pages

Attackers upload fake login, banking, email or brand impersonation pages under a compromised WordPress domain.

PhishingRead guide →
Medium

XML-RPC Brute Force Attack

Attackers abuse xmlrpc.php to attempt password attacks or amplify login attempts against WordPress.

Authentication AbuseRead guide →
High

Malicious MU Plugin

Malware hides in must-use plugins because they load automatically and are easy to miss in normal plugin screens.

PersistenceRead guide →
Medium

WordPress SEO Spam Pages

Attackers create or generate spam pages for pharma, casino, adult, gambling or counterfeit product searches.

SEO SpamRead guide →
High

WordPress Malware Reinfection

Malware returns after cleanup because the root cause, backdoor, credentials or hosting-level compromise was not fixed.

Recurring InfectionRead guide →

Open incident

Send the hacked site. We’ll take it from here.

Tell us what happened. We’ll review the case and reply with the safest recovery path.

  • Human review
  • Root-cause focused
  • Clear next steps