Quttera ThreatSign – Web Malware Scanner for WordPress

Quttera ThreatSign – Web Malware Scanner for WordPress has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 3 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 6.8 out of 10. 2023 was the busiest year with 2 disclosures.

The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (33%). Other recurring categories include Path Traversal, Server-Side Request Forgery (SSRF).

Every one of the 3 issues recorded for Quttera ThreatSign – Web Malware Scanner for WordPress has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, most of them (2) reported by Dmitrii Ignatyev. Quttera ThreatSign – Web Malware Scanner for WordPress is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all Quttera ThreatSign – Web Malware Scanner for WordPress vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.8CVE-2023-6222

Quttera Web Malware Scanner <= 3.4.1.48 - Authenticated (Administrator+) Directory Traversal via ShowFile

Read the full analysis

Vulnerability Records

3 records
Quttera ThreatSign – Web Malware Scanner for WordPress banner
Latestv4.1.0.35

Quttera ThreatSign – Web Malware Scanner for WordPress

quttera

Author

quttera

3.9(47)
78/100
Last Updated
2026-09-10 (3d ago)
Active Installs
10,000+
Downloads
4,680,531
Requires WP
3.3.2+
Requires PHP
7.2+
Tested up to
WP 7.1
Created
2012-06-07 (15y ago)

Quttera ThreatSign protects your WordPress website with multi-layered security: Malware Detection: Powered by Quttera’s AI-driven heuristic engine, the scanner detects malicious PHP, obfuscated JavaScript, hidden iframes, redirects, spam, SEO malware, and credit-card skimmers targeting checkout pages. The plugin performs on-demand scans directly from your WordPress admin and checks your domain against more than 40 global security authorities, including Google, McAfee, Norton, and Yandex. Detection capabilities are continuously enhanced using insights from Quttera’s worldwide threat intelligence network. Brute Force Protection: Prevents unauthorized login attempts with IP locking, configurable rate limiting, and environment-aware protection policies. Supports both shared hosting (aggressive locking) and dedicated servers (progressive delays). Includes emergency bypass mechanism for critical situations. Bot Protection: Layered defense against automated attacks using multi-stage risk evaluation, token-bucket rate limiting, and legitimate bot recognition (Googlebot, Bingbot, etc.). Protects REST API, XML-RPC, and WooCommerce endpoints with endpoint-specific risk scoring. Admin User Monitoring: Real-time detection and alerting for unauthorized admin additions, removals, and role changes with database audit trail and snapshots. For complete protection—including automated malware removal, scheduled scanning, WAF, and 24/7 monitoring—you can upgrade to a ThreatSign Website Security plan. Malware Detection Features: One-click on-demand scans from WP admin 0-day (unknown threat) detection via heuristic & behavioral analysis Detection of malicious PHP (backdoors, shells, injections) Detection of obfuscated or polymorphic JavaScript Identification of malicious iframes, redirects & hidden links Detection of spam & SEO malware Checkout skimmer detection Inspection of WordPress core file integrity Detection of alien or unauthorized files in core directories External links and outbound reference analysis Blacklist checks across 40+ security authorities Cloud-based scanning to reduce server resource load Detailed investigation reports with severity levels Brute Force Protection Features: IP-based locking with configurable thresholds Multi-stage failure detection with soft and hard locks Environment-aware policies for shared hosting and dedicated servers IP whitelist/blacklist with CIDR notation support Emergency bypass mechanism via constant or filter User account lockout alerts via email Combo-lock (IP + username) detection Rate limiting with progressive delays Bot Protection Features: Multi-stage risk evaluation with heuristic analysis Token-bucket rate limiting across multiple lanes (global, REST, XML-RPC, checkout, cart) Legitimate bot recognition (Googlebot, Bingbot with elevated rate limits) REST API enumeration and authentication protection WooCommerce endpoint protection (checkout & cart) Configurable operation modes (Observe, Balanced, Aggressive) Risk-based challenge mechanisms and exponential backoff Admin User Monitoring Features: Real-time detection of admin user additions and removals Admin role change tracking Database snapshot comparison for audit trail WP-Cron scheduled checks (1-minute intervals) Immediate detection via WordPress hooks Email alerts for unauthorized changes Comprehensive alarm system integration If you need malware removal assistance, contact us at support@quttera.com or sign up for any of our ThreatSign annual plans, which include cleanup & blacklist removal: https://quttera.com/anti-malware-website-monitoring-signup Credits Quttera Plugin’s other home WordPress Malware Scanner

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C