WordPress Security · Incident Response · Hardening

Your WordPress site is already a target.

It isn't if, it's when. FDesign's WordPress security services keep your site clean, patched and hardened. When it's hit, the response starts before the damage spreads.

Running WordPress? You're in the ~43% of the web that absorbs the most automated attacks, every single day.

This row should not exist. GET /wp-login.php?_w2s=827abb28 is a backdoor.

The stakes

What a hacked site actually costs

A "small" hack rarely stays small. Here's what you lose, in practice.

01

Downtime & sales

Every hour offline is lost orders, and customers who don't come back.

02

SEO & blocklist

"This site may be hacked" in Google, deindexing, and rankings built over years, gone.

03

Data & GDPR

A customer-data breach means legal exposure, disclosure duties and fines.

04

Reputation & trust

Spam redirects, card skimming at checkout, defacement. Your brand pays the bill.

The threat

How they get in

Most attacks aren't targeted. They're bots scanning millions of sites for the same known gap.

Unpatched core & plugins #1

One known vulnerability in an old version is enough. The patch exists, the site just never got it.

Rogue-admin backdoors

Hidden admin accounts that recreate themselves and stay invisible in the dashboard.

Malware & redirects

Code that sends your visitors to phishing or serves malware to everyone but you.

SEO spam & skimming

Hidden spam links that eat your ranking, or skimmers stealing cards at WooCommerce checkout.

This isn't theory. Here's what FDesign saw in August 2026.

● Real incident · August 2026

The wave of "w2s" admins

Same compromise, site after site: rogue admins named w2s-•••, planted by the WordPress core exploit chain known as wp2shell. Here's how FDesign closed the door.

02 Dec 2025
WordPress 6.9

A latent flaw ships

6.9 introduces the batch-route confusion that opens the chain. Nobody knows yet, and every 6.9.x release inherits it.

17 Jul 2026
WordPress 6.9.5

Disclosed and patched

wp2shell goes public (CVE-2026-63030 + CVE-2026-60137). 6.9.5, 7.0.2 and 6.8.6 close it, with forced auto-updates. Public exploits follow within days.

03 Aug 2026
still on 6.9.4

The door opens

Sites that never updated, ~3 weeks after the fix, get hit. The exploit creates rogue admins (w2s-•••) and plants plugins.

How it worked: an anonymous request abused a REST API batch-route confusion (CVE-2026-63030) to reach an unauthenticated SQL injection in WP_Query (CVE-2026-60137). Chained, they escalated to remote code execution that created an administrator account and uploaded a malicious plugin. That account was the w2s-••• user. Those plugins were the payload.

What FDesign did

  1. Removed the unauthorized administrators immediately.
  2. Updated core, closing the SQL-injection vector itself.
  3. Rotated keys/salts in wp-config.php and changed the DB password. Stolen sessions invalidated.
  4. Found & deleted the attacker-planted plugins. One site needed root access to remove the attacker's folder.
  5. Checked for persistence in mu-plugins, autoloaded options and cron, so the backdoor couldn't return.
The lesson

Deleting the user and updating isn't enough. This class of backdoor rebuilds itself from a hidden persistence point. Without a reinfection check, a site "gets cleaned" and re-infects within days.

Sources WordPress 6.9.5 release notes · WordPress advisory: RCE chain (CVE-2026-63030) · WordPress advisory: SQL injection (CVE-2026-60137) · CISA Known Exploited Vulnerabilities
Incident response carried out in August 2026. Dates and vulnerabilities verified against official sources. Client names and indicators anonymized.
The method

Five steps, not one plugin

Security isn't a button. It's a process that runs continuously.

01 / Identify

Audit

FDesign scans the site for exposed areas, existing compromises and outdated versions.

02 / Protect

Harden

WAF, least-privilege, 2FA, wp-login lockdown, correct config, always patched.

03 / Detect

Monitor

File-integrity monitoring & alerts on login and traffic anomalies, 24/7.

04 / Respond

Respond

Cleanup, backdoor removal, persistence check, blocklist delisting.

05 / Recover

Recover

Secure backups, tested restore and post-incident re-hardening.

Packages

Pick your level of protection

FDesign's WordPress security services run from emergency rescue to continuous, managed protection.

1.  Malware Removal & Recovery

One-off cleanup
1 Site
From €190

One compromised WordPress site, back online fast.

  • Full diagnosis & malware removal
  • Backdoor & persistence check
  • Google blocklist delisting
  • Post-clean hardening & guarantee
Request cleanup
Custom
On assessment

WooCommerce, many sites, or severe infections.

  • WooCommerce / eShop, from ~ €490
  • Multiple or recurring infections
  • Scoped after diagnosis
  • No hidden charges
Get a quote

2.  Managed Security

Monthly protection
1 Site
From €49 / month

Continuous protection for one WordPress site.

  • 24/7 Wordfence monitoring & WAF
  • Tested core & plugin updates
  • Daily off-server backups
  • Priority incident response (SLA)
Start protection
Custom
On assessment

WooCommerce, more sites, or a higher SLA.

  • WooCommerce / eShop tier
  • More than 5 sites
  • Custom SLA & reporting
  • Scoped to your stack
Get a quote

All prices exclude VAT (24%).

Who does the work

Hands-on security work since 2015 by FDesign

FD

FDesign

WordPress Engineering & Security · Athens

FDesign has built, maintained and hardened WordPress and WooCommerce sites since 2015, based in Athens. The work is hands-on, from incident response and malware cleanup to the day-to-day maintenance of production sites.

Since 2015 WordPress · WooCommerce Athens, GR

"Excellent team, with the know-how to meet demanding clients' needs. Great support too!"

Danae · FDesign client

"Fast, effective cooperation at a reasonable cost."

Constantine · FDesign client

"Professionalism that isn't a given in this industry. Thank you."

Anastasia · FDesign client
FAQ

What people ask before starting

Isn't a security plugin like Wordfence enough?

A plugin is a tool, not a plan. FDesign runs Wordfence on every site it manages, and it's a strong one: firewall, malware scanning, login security. But it doesn't patch for you, doesn't check for persistence after a hack, and won't act on its own when something real slips through. Managed security is the tool plus someone who reads it and responds.

I'm on managed hosting, aren't I covered?

Managed hosting protects the server, not necessarily your site. A vulnerable plugin, a weak password or an unpatched core are still on you. Most compromises enter through the application, not the server.

I'm already hacked. What now?

Don't panic and don't randomly delete files, you may lose the trail. Contact FDesign for an emergency cleanup: we remove the malware, check for hidden backdoors that would bring it back, and get you off blocklists.

How fast do you respond to an emergency?

Monthly-plan clients get priority with an agreed response time (SLA). For non-clients, we start with an immediate assessment and give you a realistic timeline before we begin.

Do you only work with WordPress?

No. WordPress and WooCommerce are where FDesign goes deepest, but the work also extends beyond WordPress when a project requires it. Alongside WordPress Security, FDesign handles e-commerce and eshop design, business websites, brand and logo design, website maintenance and support, SEO, Google Analytics setup, email marketing, social media integration, print design and product design. FDesign also covers the wider stack around a website: server, Cloudflare, DNS and email.

● Start here

Every day on an unpatched core is a door left open.

Start with a free security audit and see exactly where your site is exposed, with no commitment.

✓ Guaranteed cleanup. If it's not clean, you don't pay.