SECURITY FINDING
Injected script or iframe in a WordPress post
What it is
A published post or page contains a <script src> or iframe loading code from an external domain. Unless it's an embed, ad or analytics snippet added on purpose, this is very likely an injection — attackers plant scripts inside post content to redirect visitors, show spam, or steal data.
How to fix it
Open the flagged post in the editor, switch to the code/HTML view, and delete the unknown script or iframe tag if it wasn't added on purpose. If several posts are affected, restore the database from a clean backup and change every password.
In depth
An attacker gained access to your database and created or modified post number 346 without your permission. This is dangerous because attackers typically insert malicious links or spam into these posts, which damages your site's reputation and can result in Google penalties. To fix this, go into your WordPress dashboard, find that post in the Posts section, and delete it by clicking Trash. Then immediately change the password for all WordPress administrator accounts and also change your hosting account password. Finally, update WordPress, all your themes, and all your plugins to the newest versions available, and run a security plugin like Wordfence or Sucuri to scan your site and remove any malware.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.