WPSecureOps

Glossary · Malware

A malicious URL was found in a comment

Wordfence type
commentBadURL
Category
Malware
Severity
Medium

A comment on the site links to a known-bad domain.

What Wordfence found

Wordfence checked comment content against its URL blocklist and found a match. Unlike an injection, this often arrives through the ordinary comment form.

Why it matters

It is usually spam rather than a compromise, but published comments linking to malware still expose visitors and damage the site's standing with search engines. Volume matters more than any single comment: a flood suggests moderation is off.

How to fix it

  1. 1Delete the comment rather than marking it as spam if it is already published.
  2. 2Check comment moderation settings — require approval for first-time commenters at minimum.
  3. 3If there are many, look at whether a plugin is auto-approving.
  4. 4Consider disabling comments entirely on sites that do not use them.

How WPSecureOps treats it

The connector reports this as commentBadURL. WPSecureOps files it under Malware and bands it by the numeric severity Wordfence assigns, so findings of this kind from every site you manage arrive in one queue rather than one email per site. Titles and descriptions are stripped of HTML and the site's absolute path is replaced before anything leaves the server.

See this finding in context