WordPress

Common WordPress Security Issues and Simple Steps to Prevent Them

By the Domain India teamPublished 10 min read
Knowledge base article
Contents (10 sections)

WordPress runs a huge share of the web, so bots probe WordPress sites all day for the same handful of weaknesses. Most of them have simple fixes that take minutes. This article lists the common problems, what each lets an attacker do, and the step that closes it.

Key takeaways

The most common WordPress security problems are outdated or pirated plugins and themes, weak or reused passwords without two-factor authentication, an open XML-RPC endpoint, too many administrators, and PHP running in the uploads folder. Update everything weekly, delete what you do not use, use a password manager and 2FA, block xmlrpc.php if you do not need it, lock down uploads and keep your own backup. Domain India's servers add a firewall and automatic malware cleanup, but they cannot update your plugins for you.

1. The common issues at a glance

IssueWhat it lets an attacker doSimple step
Outdated plugins, themes or coreUse a published hole to upload files or create an administratorUpdate weekly; turn on auto-updates for trusted plugins
Unused, abandoned or nulled codeAttack files you forgot about, or use a backdoor that came with a pirated themeDelete what you do not use; never install nulled themes or plugins
Weak or reused passwordsLog in with a guessed password or one leaked from another siteUnique passwords from a password manager, plus 2FA
Open XML-RPCTest hundreds of passwords in one requestBlock xmlrpc.php if nothing you use needs it
SQL injection and XSSRead your database or run scripts in an administrator's browserKeep plugins updated; the server firewall blocks many attempts
Too many administratorsTurn one stolen login into full controlLowest role that works for each person
No HTTPSRead passwords and cookies sent in plain textFree SSL certificate and a redirect to https
PHP running in uploadsRun a malicious file uploaded through a weak formBlock PHP in wp-content/uploads
No monitoring or backupsStay hidden for weeks, leaving you nothing clean to go back toA security plugin with alerts, and your own backups

For how each route works in detail, see why and how WordPress websites get hacked.

Diagram of five ways into a website: outdated plugin, weak password, unvalidated upload, injection in your own code and a readable secret, all on the customer side of the line
The common ways in, and which side of the line each one sits on.

2. Outdated, unused and pirated plugins and themes

Most WordPress hacks start here. Once a plugin's security fix is public, bots scan for sites that have not updated.

  • Update every week, or turn on auto-updates for the plugins and themes you trust (Plugins › Enable auto-updates). Leave WordPress's automatic core security updates on.
  • Delete, do not just deactivate, plugins and themes you are not using. Their files are still on the server and can still be attacked. Keep one default theme as a fallback.
  • Replace abandoned plugins. If a plugin's WordPress.org page shows no update for over a year, or says the plugin was closed, find a maintained alternative.
  • Never install nulled themes or plugins. Pirated copies often contain a hidden backdoor and can never be updated. Buy from the developer or use free plugins from the WordPress.org directory.

3. Weak passwords and brute-force logins

Bots try common usernames such as "admin" with common passwords, and replay email and password pairs leaked from other websites.

  1. Use a password manager
    and a long, unique password for WordPress, your control panel, FTP, the database and your email. See best password managers.
  2. Turn on two-factor authentication
    for every administrator and editor. WordPress core does not include 2FA, so add it with Wordfence, Solid Security (formerly iThemes Security) or the free Two Factor plugin, and use an authenticator app rather than SMS.
  3. Limit login attempts.
    Most security plugins include this; Limit Login Attempts Reloaded does only this job.
  4. Retire the "admin" username.
    Create a new administrator, log in with it, and delete the old account, assigning its posts to the new user.

Block XML-RPC if you do not use it

xmlrpc.php is an old remote-publishing interface. One request to it can test hundreds of passwords, which slips past simple login limits. Jetpack and some older publishing apps still need it. If you use neither, block it with your security plugin, or add this to the .htaccess file in your WordPress folder:

apache
<Files xmlrpc.php>
    Require all denied
</Files>

Older guides show order deny,allow, which is outdated Apache 2.2 syntax.

4. SQL injection and cross-site scripting (XSS)

These are bugs inside plugins and themes, not settings you switch off.

  • SQL injection: a plugin puts visitor input straight into a database query, and the attacker's input changes the query, for example to read user records or create an administrator.
  • XSS: a plugin prints visitor input back into a page without cleaning it, so the attacker's script runs in the browser of whoever views it, possibly you, logged in as administrator.

The fix is the same as section 2: update promptly and remove what you do not need. A web application firewall is a second layer. On our cPanel servers, Imunify360's firewall runs with its full ruleset and WordPress protection on by default (measured 20 September 2026), so many common injection attempts are blocked before they reach WordPress.

5. Too many administrators

Every administrator is a full key to the site. Give each person their own login with the lowest role that works:

  • Editor or Author for people who write and publish content;
  • Administrator only for people who install plugins and change settings.

Remove accounts for people who have left, and check Users every month. An administrator you did not create is the clearest sign of a hack. Also look under Users › Profile › Application Passwords and revoke any you do not recognise.

6. HTTPS and SSL certificates

Without HTTPS, login passwords and session cookies cross the internet in plain text. You do not need to buy a certificate for a normal website:

  • On our cPanel servers, free Let's Encrypt certificates are issued and renewed automatically (AutoSSL, measured 20 September 2026).
  • On DirectAdmin and Webuzo, request the free certificate from the panel.

Then set both WordPress addresses in Settings › General to https://, and make sure plain http:// addresses redirect. A plugin such as Really Simple Security (formerly Really Simple SSL) can handle the redirect and fix mixed-content warnings. See how to enable free SSL.

7. Lock down files

Stop PHP running in the uploads folder. Images never need to execute, but a malicious upload does. Create wp-content/uploads/.htaccess containing:

apache
<FilesMatch "\.(php|phtml|phar)$">
    Require all denied
</FilesMatch>

Test it by uploading a file called test.php there with the File Manager and opening it in your browser. You should get a 403 error. Then delete the test file.

Turn off the dashboard code editor. Add this line to wp-config.php, above "That's all, stop editing":

php
define( 'DISALLOW_FILE_EDIT', true );

Use sane permissions: 755 for folders, 644 for files, and 640 or 600 for wp-config.php if the site still loads. Never 777.

What about the wp_ table prefix?

Changing the default wp_ database prefix is often listed as a security step. It only slows down the crudest automated attacks, and changing it on a live site can break it if one table or option is missed. Choose a different prefix when you install a new site, but on an existing site, spend the time on updates and 2FA instead.

8. Monitoring and backups

On our cPanel servers, Imunify360 scans new and changed files as they are written and again every week, removes malicious code automatically, and keeps the original file for 14 days (measured 20 September 2026). Two things it does not do:

  • you cannot start an Imunify360 scan yourself from the control panel;
  • you are not emailed when malware is found or cleaned.

So add your own early warning: one security plugin, such as Wordfence, Solid Security or Sucuri Security, with email alerts for new administrators, changed files and vulnerable plugins (two security plugins together often conflict), and your site verified in Google Search Console.

For backups, our cPanel and DirectAdmin hosting runs weekly JetBackup 5 backups, keeping five copies, which you can download or restore from the panel. Treat them as a safety net and keep your own copies off the server too, because malware can sit unnoticed for longer than a week. See how to restore or download a backup with JetBackup.

If your site has already been hacked, follow the security checklist for hacked websites.

9. Where Domain India hosting fits

The host secures the server; you secure the WordPress site on it. On our cPanel and DirectAdmin servers, CloudLinux CageFS keeps each hosting account isolated from the others, and Imunify360 and the CSF firewall run server-wide, with the same configuration for every account on the server. You get the same protection on every plan, so choose a plan by resources, not security.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details
DA Starter
₹100/mo + GST
  • 10 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 5 Email Accounts
See plan details

Plan cards show live Domain India list prices, excluding 18% GST. Hosting cannot update your plugins or stop someone who logs in with your real password, so the steps above are still yours. For the full list of tips, see useful tips to secure WordPress.

What is the most common WordPress security issue?

Outdated plugins and themes. When a security fix is published, bots scan for sites that have not updated yet. Update every week or turn on auto-updates, and delete plugins and themes you do not use.

Do I need a security plugin if my hosting has a firewall?

It is still worth having one. The server firewall blocks many attacks, but a security plugin adds login limits, two-factor authentication and email alerts for new administrators and changed files. On Domain India shared hosting you are not emailed when the server's scanner removes malware, so plugin alerts fill that gap.

How do I block xmlrpc.php in WordPress?

Use the XML-RPC option in your security plugin, or add a Files block for xmlrpc.php with "Require all denied" to the .htaccess file in your WordPress folder. Do not block it if you use Jetpack or an app that publishes through XML-RPC.

How do I stop PHP files running in the uploads folder?

Create an .htaccess file in wp-content/uploads with a FilesMatch rule that denies .php, .phtml and .phar files. Test it by uploading a test.php file and checking that your browser shows a 403 error, then delete the test file.

Does Domain India back up my WordPress site?

Domain India cPanel and DirectAdmin hosting runs weekly JetBackup 5 backups and keeps five copies, which you can download or restore from your panel. Keep your own copies off the server as well.

Ready to secure your site? Start with updates and 2FA today, work through the WordPress hardening guide, and open a support ticket if something on your hosting account looks wrong.

WordPress hosting with the server side handled

CloudLinux account isolation, Imunify360 with automatic malware cleanup, a web application firewall and free SSL on Domain India cPanel hosting.

See cPanel hosting plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app