Hacker attacks in Croatia on websites have existed since the Internet and the creation of websites. The biggest development of WordPress was in 2008, but WordPress was not yet very popular, so at that time there was not much talk about the vulnerabilities of WordPress. The first time we actually saw the exposed vulnerabilities of WordPress was during the hacking in 2008. The primary attacks of hackers during this fiasco were the root directory of WordPress site, wp-config.php file, .htaccess files, plugins and themes. WordPress began to gain strength until 2008, and at the same time began to gain a rather bad reputation due to its security measures. The year 2008. TechCrunch picked up the story of the WordPress hack fiasco: “If you do not currently have the latest version of WordPress, there is a high probability that your page is already compromised.” - TechCrunch
Of course, this was just the beginning of a crazy journey through WordPress's list of vulnerabilities that was constantly increasing. In fact, WordPress users already started to be cautious in 2008, as in 2007 their own WordPress servers were subjected to a series of attacks and hacker attacks generated vulnerabilities embedded in WordPress patches themselves.
2009. (Year of vulnerability)
WordPress security team had hard times. The reason is that they completely fail to patch up vulnerabilities on time (sometimes for years), but since 2009 they have been publishing a huge amount of security updates.
2009 was the first year we saw a ton of security updates that required website owners to upgrade WordPress. Unfortunately, hackers who find vulnerabilities a few days after each upgrade also continued.
2010 (Tim Thumb)
2010 was another big year for hackers and there was a lot of website updates and vulnerabilities, but we want to focus on the big deal – TimThumb. Why do we want to focus on TimThumb? We think this is a pretty good example of a state of security and especially the insane ability to ignore vulnerabilities for a very long time.
TimThumb is a .php file name that contains image sizes. So, scripts, themes, extensions (really all) have been using scripts for years that would change the dimensions of the file within TimThumb. And, all those years, the websites were hacked. Lots of websites.
2010./2011.
There was a time when some of the first applications started to be sent to TimThumb. Websites were compromised, and hackers literally fired orders at websites and shut them down using vulnerabilities in TimThumb. TimThumb was still used — and widely — to hijack websites. Hacker attacks went over critical website files, WordPress still ignored it, and thousands of websites were still vulnerable. That's almost five years. Let's say it again — five years. TimThumb remains one of the top three security risks for plugins to date, according to Sucuri's latest report on the hacked website.
2011. 2013-2013 (Greater websites tend to fall)
Around 2011, WordPress began to dominate the OSS CMS market. Tons of websites flocked to WordPress. This is about the time when WordPress has become completely vulnerable to “problem-prone”. Between 2011 and 2013, more than 50 vulnerabilities emerged – many of which were easy to do. Hackers have demolished huge websites and DDOS everything from companies to political campaigns.
Around that time, videos began to appear showing people downloading WordPress websites in 5 minutes (and with ease).
2018 and beyond…
Between 2013 and 2018, more than 275 key vulnerabilities emerged. Countless others for all free and commercial accessories that exist. In 2017, WordFence reported that a hacker could even use a WordPress installer to take control of your website.
At a time when the internet was not yet so developed, website maintenance was not done regularly because there was no need given the relatively rare cases where hacker attacks were on the site. However, today, non-maintenance of websites can be expensive to pay, as attacks on sites are becoming more frequent. According to Sucuria, a large increase in attacks on non-maintenance of wordpress pages was observed by injecting the code onto the page and creating a background entry on the page via php.
Hacker attacks and code insertion
Adding code is done through a plugin, which is a legitimate plugin on the wordpress repository so that the code is activated when someone visits the page with their computer. It is believed that over 4000 websites are infected in this way in the world. As can be seen on this graph, there has recently been a multiple increase in the removal of plugins from the wordpress repository and thus hacker attacks.

What this code does is that hacker attacks start from the back entrance and attackers automatically take control of the website. Malicious code is inserted via a database into the so-called ‘wp_posts’ table’, which is an additional problem because code finding tools are very often unable to detect infection, precisely because of the position of the code. In order to be able to take control of the website, attackers install the code in new pages or posts as follows:

When the code is activated, an input is created that is stored on the site server in the root pages with this code name: 3e9c543a6b54r.php. The activation of the code is done through the following IP addresses:
- 91.193.43.151
- 79.137.206.177
- 212.113.119.6
How to Protect Your Website from Hackers
Sucuri recommends, for this reason, to prevent hacker attacks so that on all websites old plugins are necessarily upgraded with newer versions, and plugins that are not used are simply deleted from the site. Namely, old plugins that have not been updated just allow the infected code to be injected.
Given all the above, our most important priority in maintenance is a regular update because hacker attacks in 2023 are prevented with every update, of course only on stable versions of the system connection, plugins and themes. Although the internet seems to be a safe space, very often it is misleading and attackers just want users to relax so that they can carry out their evil intentions.
How vulnerable pages can be is also shown by the fact that Wordfence Threat Intelligence initiated a critical vulnerability detection process in the Elementor plugin, which enabled each authenticated user to load an arbitrary PHP code. Elementor is one of the most popular WordPress plugins and has been installed on over 5 million websites.
If you have any questions on this topic, please feel free to contact.
