SECURITY FINDING
Injected script or iframe in a WordPress post
What it is
A published post or page contains a <script src> or iframe loading code from an external domain. Unless it's an embed, ad or analytics snippet added on purpose, this is very likely an injection — attackers plant scripts inside post content to redirect visitors, show spam, or steal data.
How to fix it
Open the flagged post in the editor, switch to the code/HTML view, and delete the unknown script or iframe tag if it wasn't added on purpose. If several posts are affected, restore the database from a clean backup and change every password.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.