A plain-English recap of September 2026's biggest website hacks β WordPress plugin exploits, fake-CAPTCHA malware, and hacked-site warnings β and what to do.
If you own a website and the last few weeks have felt noisier than usual, you're not imagining it. The website hacks of September 2026 followed the same depressing pattern we clean up at DS Web Solutions every week: automated attacks hammering a handful of known WordPress plugin vulnerabilities, fresh waves of malicious redirects and fake-CAPTCHA malware, and a steady trickle of business owners discovering a "this site may be hacked" label on their own company name. None of it was personal, almost all of it was preventable, and most of the sites hit were running software that was out of date by weeks or months. Here's an honest recap of the latest website malware trends of 2026, what actually happened, and what it means for your site.
WordPress plugin vulnerabilities were (again) the main event
The biggest story in website security this month wasn't a clever new hacking technique β it was the same old one working at scale. The latest WordPress vulnerabilities of 2026 kept following a brutal timeline: a researcher discloses a flaw, a patch ships, and then hundreds of thousands of sites that never updated get mass-exploited by bots scanning the entire web for the unpatched version. September's standouts:
- A critical unauthenticated file-upload flaw in the WooCommerce Wholesale Lead Capture plugin (CVE-2026-27540, CVSS 9.8) let attackers upload PHP webshells and seize full control of a site. Wordfence reported blocking over 100,000 exploit attempts tied to it β and the patch had already been available for months, so every site hit was running an outdated version.
- A remote-code-execution flaw in a widely installed backup plugin left an estimated 3+ million sites exposed weeks after the fix shipped, with working exploit code circulating publicly. Backup plugins are a favourite target precisely because they can read and write every file on the site.
- Year-old authentication-bypass flaws in popular add-on plugins were still being actively exploited to install backdoor "plugins" and take over sites β proof that a vulnerability doesn't stop being dangerous just because the headline moved on.
The through-line is the one we repeat constantly: it's a numbers game run by bots, not a targeted hit. A single unpatched plugin is all it takes. If you're unsure why a plugin you forgot you installed can take down your whole site, our guide to how WordPress sites get hacked walks through exactly how that entry point works.
Nobody is picking on your business. A bot found an outdated plugin, and your site happened to be on the list β along with a hundred thousand others.
Fake-CAPTCHA "ClickFix" malware kept spreading through hacked sites
One of the defining website malware trends of 2026 is the "ClickFix" fake-CAPTCHA attack, and it stayed busy through September. Here's the twist that makes it so dangerous: attackers compromise a legitimate website, then make it display a fake "verify you're human" box. Instead of a normal checkbox, it instructs the visitor to press Windows+R, paste a command, and hit Enter β which quietly runs malware that steals browser passwords, crypto wallets, and VPN credentials. The victim installs it themselves, thinking they're just passing a CAPTCHA. Earlier in 2026, Malwarebytes documented more than 700 education and technology websites hijacked to serve this exact trick, many of them through a critical SQL-injection flaw (CVE-2026-26980) in the Ghost CMS. For site owners the lesson is blunt: if your site is compromised, it isn't just your problem β your own visitors become the next victims, and your brand is the bait.
Malicious redirects and spam injections stayed relentless
The most common symptom we were called about in September hasn't changed in years: a site that suddenly redirects visitors to spam, ads, or a sketchy "you've won" page. Mass plugin-exploitation campaigns almost always end the same way β the attacker injects a conditional redirect script that fires for mobile or search visitors but hides from the logged-in owner, which is why so many owners swear their site "looks fine" while customers get hijacked. If that's happening to you, our breakdown of why your website is redirecting to spam explains how the script hides and why deleting the one line you can find never fixes it. The injection is the payload; the backdoors and the open plugin hole are the real problem, and they'll reinfect a half-finished cleanup within days.
The supply-chain story: when the hack comes from your dependencies
September's security news was also dominated by a software supply-chain attack that matters even if you've never heard the word "npm." A self-replicating worm nicknamed "Shai-Hulud" compromised more than 1,300 versions of popular JavaScript packages β code that gets pulled into countless websites and apps β stealing developer credentials and spreading itself to further packages automatically. The packages affected represented billions of monthly downloads. The practical takeaway for a business owner: a modern website is assembled from a lot of other people's code, and "we built it years ago and never touched it" is not the safe position it sounds like. Stale dependencies are an attack surface, whether they live in a plugin directory or a build pipeline.
"This site may be hacked," Google Safe Browsing, and antivirus blocks
Every one of the campaigns above produces the same downstream pain: Google Safe Browsing detects the injected malware or redirect and starts warning users away. That shows up as a grey "this site may be hacked" label in search results, or β far worse β a full red "deceptive site ahead" screen that blocks visitors before your page even loads. We saw a steady stream of owners discovering these flags in September, usually days after the infection, often with no idea what triggered them. The warnings aren't a punishment; they're a symptom, and Google won't lift them until the site is genuinely clean. If you've been flagged, follow the right order in our step-by-step guide to removing Google's "this site may be hacked" warning β clean first, request review second, because a review submitted on a still-infected site just fails.
And Google isn't the only gatekeeper. Endpoint antivirus suites block hacked sites too β Kaspersky being one of the most aggressive. Its Web Anti-Virus component checks every site a user visits against the Kaspersky Security Network reputation database, and the moment your domain is flagged for malicious code or a phishing redirect it throws up a full-screen "Dangerous website" or "Visiting an untrustworthy website has been prevented" notice and simply refuses to load the page. This is arguably worse than a Google flag: it hits your most loyal, security-conscious customers β the ones who pay for real protection β and it happens silently on their machine, so you never see it and they rarely tell you; they just quietly assume your business can't be trusted. Other major antivirus and browser vendors run their own blocklists the same way, and like Google they won't clear your domain's reputation until it's independently verified clean. The practical lesson is that a single infection doesn't just cost you search traffic β it can lock out a slice of your audience entirely across every device their antivirus protects.
What this month means for your website
Pull it all together and the advice is unglamorous but effective. Update everything β core, plugins, and themes β promptly, because September's victims were overwhelmingly sites running software patched weeks earlier. Delete plugins you don't use; an inactive plugin is still a live vulnerability. Use strong, unique admin passwords with two-factor authentication, since credential-stuffing bots never sleep. And run a reputable security plugin with a firewall so a new threat is caught in minutes. Not sure whether you've already been caught? Walk through the warning signs your website has been hacked β a slow site, strange pages in Google, a hosting suspension email, or an admin account you don't recognize are the ones to act on fast.
The cheapest cleanup is the update you did last Tuesday. The most expensive is the one you do after your customers find the spam first.
If your site got caught in one of these waves
If you're reading this because your site is already redirecting, flagged, or acting strange, don't fight it file-by-file on a live server β that's how backdoors get missed and the infection comes back. This is exactly what our Code Red service is built for: emergency website malware removal with same-day response, a flat price quoted upfront, a full hunt for every backdoor, and the specific plugin or dependency that let the attack in closed so it can't happen again. If Google has blacklisted you, we file the Safe Browsing review as part of the job. Whether you were hit by one of September's plugin campaigns or just want a clean site going into the next one, you can get your hacked site cleaned and hardened in a single pass β reach us by phone or the contact form on our homepage and we'll tell you honestly where you stand before you spend a dollar. And if your site is currently showing visitors a fake CAPTCHA or a spam redirect, that live infection is precisely what professional malware cleanup removes, root cause and all.
References
- BleepingComputer β Hackers target WordPress sites via third-party WooCommerce plugin (CVE-2026-27540)
- Malwarebytes β 700+ education and tech websites hijacked in huge ClickFix malware campaign
- CSA Singapore β Ongoing npm Supply Chain Attack ("Shai-Hulud" Worm)
- Google Safe Browsing
- Kaspersky Support β What to do if a website is blocked by a Kaspersky application (Web Anti-Virus / Kaspersky Security Network)
This article is general educational information, not professional, medical, or purchasing advice. External links are provided for reference; DS Web Solutions Inc. is not affiliated with and does not endorse any third-party brand or organization listed.




