• About Us
  • Privacy
  • Terms
    • DMCA
  • AdChoices
  • Contact Us
  • Careers
  • Dictionary
  • Donate
No Result
View All Result
Nyongesa Sande
  • Radio
  • Events
  • How To
  • AI
  • Business
    • Shop
    • Money
    • Billionaires
  • Finance
  • Gadgets
  • Lifestyle
  • Sports
  • Autos
Nyongesa Sande
No Result
View All Result
  • Radio
  • Events
  • How To
  • AI
  • Business
  • Finance
  • Gadgets
  • Lifestyle
  • Sports
  • Autos

Home » WordPress security issues

WordPress security issues

December 12, 2023
in Cybersecurity
Reading Time: 5 mins read
A A
FacebookXTelegramWhatsappLinkedIn

WordPress is the world’s most popular content management system. As its developers like to point out, over 40% of all websites are built on WordPress. However, this popularity has its downside: such a huge number of potential targets inevitably attracts malicious actors. For this very reason, cybersecurity researchers carefully investigate WordPress and regularly report various problems with this CMS.

ADVERTISEMENT

As a result, it’s not uncommon to hear that WordPress is full of security issues. But all this attention has a positive side to it: most of the threats and the methods to combat them are well known, making it easier to keep your WordPress site safe. That’s what we’ll be discussing in this article.

1. Vulnerabilities in plugins, themes, and the WordPress core (in that order of descending importance)

In all the lists of WordPress security issues available on the internet, it’s things like XSS (cross-site scripting), SQLi (SQL injection), and CSRF (cross-site request forgery) keep popping up. These attacks, alongside various others, are made possible due to vulnerabilities in either the WordPress core software, its plugins or themes.

It’s important to note that, statistically, only a small fraction of the vulnerabilities are found in the WordPress core itself. For example, for the whole of 2022, a mere 23 vulnerabilities were discovered in the WordPress core software — which is 1.3% of the total 1779 vulnerabilities found in WordPress that year. Another 97 bugs (5.45%) were discovered in themes. Meanwhile, the lion’s share of vulnerabilities were found in plugins: 1659 — making up 93.25% of the total.

ADVERTISEMENT

It’s worth mentioning that the number of vulnerabilities discovered in WordPress should not be a reason to avoid using this CMS. Vulnerabilities exist everywhere; they’re just found most frequently where they’re most actively sought — in the most popular software.

How to improve security:

  • Always update the WordPress core promptly. Though vulnerabilities are not found as often here, they are exploited more intensively, so leaving them unpatched is risky.
  • Remember to update themes — especially plugins. As mentioned, plugins are responsible for the vast majority of known vulnerabilities in the WordPress ecosystem.
  • Avoid installing unnecessary WordPress plugins — those that your site doesn’t need to operate. This will significantly reduce the number of potential vulnerabilities on your WordPress site.
  • Promptly deactivate or entirely remove plugins you no longer need.

2. Weak passwords and lack of two-factor authentication

The second major security issue with WordPress is the hacking of sites using simple password guessing (brute-forcing) or compromised usernames and passwords (credential stuffing) from ready-made databases, which are collected as a result of leaks from some third-party services.

If an account with high privileges is compromised, attackers can gain control of your WordPress site and use it for their own purposes: stealing data, discreetly adding to your texts links to the resources they promote (SEO spam), installing malware (including web skimmers), using your site to host phishing pages, and so on.

How to improve security:

  • Ensure strong passwords for all users of your WordPress site. To achieve this, it’s good to apply a password policy — a list of rules that passwords must satisfy. There are plugins available that let you implement password policies on your WordPress site.
  • Limit the number of login attempts — again, there are plenty of plugins for this purpose.
  • Enable two-factor authentication using one-time codes from an app. And again, there are WordPress plugins for this.
  • To prevent your WordPress users from having to remember long and complex passwords, encourage them to install a password manager. By the way, our [KPM placeholder]Kaspersky Password Manager[/placeholder] also lets you use one-time codes for two-factor authentication.

3. Poor control over users and permissions

This issue is connected to the previous one: often, owners of WordPress sites don’t manage the permissions of their WordPress users carefully enough. This significantly increases risk if a user account gets hacked.

We’ve already discussed the potential consequences of an account with high access rights being compromised — including those access rights issued mistakenly or “for growth”: SEO spam injection into your content, unauthorized data access, installing malware, creating phishing pages, and so on.

ADVERTISEMENT

How to improve security:

  • Be extremely careful when assigning permissions to users. Apply the principle of least privilege — grant users only the access rights they absolutely need for their tasks.
  • Regularly review your list of WordPress users, and remove any accounts that are no longer necessary.
  • Move users to less privileged categories if they no longer need elevated permissions.
  • Of course, the advice from point 2 also applies here: use strong passwords and enable two-factor authentication.

4. Malicious plugins

Aside from plugins that are “just” vulnerable, there are also outright malicious ones. For example, not long ago, researchers discovered a WordPress plugin masquerading as a page-caching plugin but which was actually a full-fledged backdoor. Its main function was to create illegal administrator accounts and gain complete control over infected sites.

Earlier this year, researchers found another malicious WordPress plugin, which was originally legitimate but had been abandoned by developers over a decade ago. Some bleeding hearts picked it up and turned it into a backdoor — allowing them to gain control over thousands of WordPress sites.

How to improve security:

  • Avoid installing unnecessary WordPress plugins. Only install the ones truly essential for your site’s operation.
  • Before installing a plugin, read its user reviews carefully — if a plugin does something suspicious, chances are someone’s already noticed it.
  • Deactivate or remove plugins you no longer use.
  • There are plugins that scan WordPress sites for malware. However, keep in mind they can’t be completely trusted: many of the latest instances of WordPress malware can deceive them.
  • If your WordPress site is behaving strangely and you suspect it’s infected, consider contacting specialists for a security audit.

5. Unrestricted XML-RPC Protocol

Another vulnerability specific to WordPress is the XML-RPC protocol. It’s designed for communication between WordPress and third-party programs. However, back in 2015, WordPress introduced support for the REST API, which is now more commonly used for application interaction. Despite this, XML-RPC is still enabled by default in WordPress.

The problem is that XML-RPC can be used by attackers for two types of attacks on your site. The first type is brute-force attacks aimed at guessing passwords for your WordPress user accounts. With XML-RPC, attackers can combine multiple login attempts into a single request, simplifying and speeding up the hacking process. Secondly, the XML-RPC protocol can be used to orchestrate DDoS attacks on your WordPress website through so-called pingbacks.

How to improve security:

  • If you don’t plan on using XML-RPC in the near future, it’s best to disable it on your WordPress site. There are several ways to do this. If you need this functionality later, it’s not difficult to re-enable it.
  • If you intend to use XML-RPC, it’s advisable to configure its restrictions, which can be done using WordPress plugins.
  • Also, to protect against brute-force attacks, you can follow the advice from point 2 of this article: use strong passwords, enable two-factor authentication, and use a password manager. By the way, this is included in the license of our product designed for protecting small businesses — Kaspersky Small Office Security.
Was this article helpful?
YesNo
Tags: WordPress security
ADVERTISEMENT
Previous Post

How does antivirus software protect my computer from malware?

Next Post

Outdated Cisco equipment under threat from firmware

RelatedPosts

Cyber crimes in Qatar: The law and how to report them
Cybersecurity

Cybersecurity Tips for Kakamega Enterprises

6 months ago

In today's digital age, enterprises in Kakamega County face increasing cybersecurity threats that can compromise sensitive data, disrupt operations, and...

Outdated Cisco equipment under threat from firmware
Cybersecurity

Outdated Cisco equipment under threat from firmware

2 years ago

Outdated Cisco equipment under threat from firmware. Devices on the border between the internet and an internal corporate network —...

Safaricom Cuts Enterprise Cyberattacks by 90% with New Security Tools
Cybersecurity

Safaricom Cuts Enterprise Cyberattacks by 90% with New Security Tools

24 hours ago

In a major development, Safaricom has announced a 90% reduction in the number of cybersecurity incidents affecting its enterprise customers....

Top 5 cybersecurity companies in Nepal
Cybersecurity

Top 5 cybersecurity companies in Nepal

2 years ago

Here's a list of the top 5 cybersecurity companies in Nepal, including their focus areas and how they contribute to...

Remcos RAT via Discord
Cybersecurity

Remcos RAT via Discord

2 years ago

Cybercriminals send the Remcos remote-access trojan under the guise of letters from a new client. Since the beginning of the...

A good reason to update Confluence
Cybersecurity

A good reason to update Confluence

2 years ago

Recently, CISA, the FBI, and MS-ISAC issued a joint advisory urging all organizations that use Confluence Data Center and Confluence Server to update the...

Safaricom Statement on Data Privacy.
Cybersecurity

Safaricom Statement on Data Privacy.

1 year ago

Nairobi, June 25, 2024 – In response to growing online conversations concerning data privacy, Safaricom PLC has issued a statement...

Cybersecurity Based on Risk and Enhanced by Managed Detection and Response (MDR)
Cybersecurity

Top Cybersecurity Certifications That Pay Well

5 months ago

Cybersecurity is one of the fastest-growing fields in tech, and demand for certified professionals has never been higher. Companies across...

FBI Issues Warning: Avoid Free File Converter Websites and Apps to Protect Your Data
Cybersecurity

FBI Issues Warning: Avoid Free File Converter Websites and Apps to Protect Your Data

8 months ago

The Federal Bureau of Investigation (FBI) has issued a public advisory urging smartphone and PC users to avoid free file...

Cybersecurity

Boramae Ransomware

8 months ago

Cybersecurity researchers have uncovered a new ransomware variant named Boramae, which poses a serious risk to Windows-based systems. First detected...

Load More
Next Post
Outdated Cisco equipment under threat from firmware

Outdated Cisco equipment under threat from firmware

Reptar: a vulnerability in Intel processors

Reptar: a vulnerability in Intel processors

ADVERTISEMENT
Nyongesa Sande

Nyongesa Sande delivers breaking news, technology updates, billionaire profiles, inventions, AI trends, and inspiring facts.

  • About Us
  • Privacy
  • Terms
  • AdChoices
  • Contact Us
  • Careers
  • Dictionary
  • Donate

©2025 Nyongesa Sande. All rights reserved.

No Result
View All Result
  • Tech News
  • Banking
  • Biography
  • Politics
  • Presidents
  • How To
  • Wiki
  • Real Estate
  • Health
  • Gadget Reviews
  • Top 10
  • History
  • Companies
  • Sports
  • Loans
  • Finance
  • Travel
  • Breaking News
  • AI
  • Electric Vehicle
  • Motivation
  • Phone Prices
  • Hosting
  • Shopping Malls
  • Africa
  • Business
  • Insurance
  • Restaurants
  • Investment
  • Classifieds
  • KenyanBaze
  • Shop Anything

©2025 Nyongesa Sande. All rights reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.