WPSecureOps

Glossary · Malware

A malicious URL was found in a post

Wordfence type
postBadURL
Category
Malware
Severity
High

Published post content links to a known-bad domain.

What Wordfence found

A URL inside a post or page matches Wordfence's blocklist. The finding names the post.

Why it matters

Post content is normally only writable by authenticated users, so a malicious link in a post is a stronger signal than one in a comment. Either an account is compromised or something is writing to the database directly — and the link is being served to every visitor of that page.

How to fix it

  1. 1Open the post and check its revision history to see who or what introduced the link.
  2. 2If no legitimate revision explains it, treat the site as compromised.
  3. 3Remove the link, then check whether other posts contain it.
  4. 4Review administrator and editor accounts for ones you do not recognise.

How WPSecureOps treats it

The connector reports this as postBadURL. WPSecureOps files it under Malware and bands it by the numeric severity Wordfence assigns, so findings of this kind from every site you manage arrive in one queue rather than one email per site. Titles and descriptions are stripped of HTML and the site's absolute path is replaced before anything leaves the server.

See this finding in context