SECURITY FINDING

Rogue database table left by malware

What it is

A database table was found that isn't part of WordPress or its plugins, and its contents look like attacker data (command-and-control info or encoded payloads). Malware hides tables like this to store its configuration so it survives a file cleanup.

How to fix it

Back up the database, then drop the rogue table. Because this is destructive, install the WordPress Plugin and let it remove the table after a backup, or export the database first and delete it manually.

In depth

Our security scan found an unauthorized table in your website's database that was created by malware, not by your WordPress installation or plugins. This rogue table stores malicious code that attackers can use to control your site remotely and reinfect it even after you remove infected files. To remove it safely, first back up your entire database using your hosting control panel or a backup plugin like UpdraftPlus. Then either use a security plugin like Wordfence or Sucuri to identify and remove the rogue table, or contact your web host's support team with the table name and ask them to delete it for you. After removal, run a full security scan to ensure no other backdoors remain, and consider changing all your WordPress admin passwords and user account credentials.

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.