WP Clinic
Log in Sign up

SECURITY FINDING

Injected script or iframe in a WordPress post

What it is

A published post or page contains a <script src> or iframe loading code from an external domain. Unless it's an embed, ad or analytics snippet added on purpose, this is very likely an injection — attackers plant scripts inside post content to redirect visitors, show spam, or steal data.

How to fix it

Open the flagged post in the editor, switch to the code/HTML view, and delete the unknown script or iframe tag if it wasn't added on purpose. If several posts are affected, restore the database from a clean backup and change every password.

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.