07/17/2026
β οΈ WordPress Website Owners: Watch for Fake Cloudflare Verification Pages
We recently identified and removed a malicious WordPress infection affecting multiple websites. Visitors on desktop computers were being shown a fake βCloudflare human verificationβ screen, while mobile visitors and logged-in administrators often saw the normal website.
This is part of a growing attack method commonly known as ClickFix. Cybersecurity researchers have documented compromised WordPress websites being used to display convincing Cloudflare-style verification pages. These prompts may attempt to trick visitors into pressing keyboard shortcuts, opening Windows Run or PowerShell, pasting commands, or downloading malicious files. (Rapid7)
In our case, the infection included:
Unauthorized WordPress plugins with generic tracking names
A malicious plugin designed to hide itself from the Plugins screen
Code that avoided displaying the payload to logged-in administrators
An unauthorized administrator account named root
A remotely controlled script that displayed the fake verification page to selected visitors
This selective behavior can make the infection difficult to detect. A website owner may see the normal site while customers, employees, or desktop visitors see the malicious page.
How this can affect a website
A compromised site may:
Block visitors from reaching the real website
Damage customer trust
Trigger browser or search-engine security warnings
Redirect visitors to malicious content
Expose visitors to credential-stealing malware
Give attackers continued administrative access
Spread across multiple websites when credentials are reused
Fake verification attacks are especially dangerous when the page tells visitors to press Windows + R, open PowerShell or Terminal, paste a command, or install something. Legitimate Cloudflare verification will not ask visitors to run commands on their computers. Microsoft reports that ClickFix campaigns are used to deliver malware and steal credentials or other sensitive information. (Microsoft)
How we resolved the issue
Our cleanup process included:
β
Removing unauthorized and malicious plugins
β
Deleting an unknown administrator account
β
Inspecting plugin, upload, and must-use plugin directories
β
Clearing WordPress, server, hosting, and CDN caches
β
Reviewing custom code and recently modified files
β
Reinstalling clean WordPress core files
β
Updating legitimate plugins and themes
β
Changing administrator and hosting credentials
β
Ending active login sessions
β
Testing across multiple browsers, computers, and networks
Clearing the cache alone may temporarily remove the visible popup, but it does not fix the underlying compromise. The malicious files, unauthorized users, and original point of entry must also be removed. Security researchers recommend keeping WordPress, themes, and plugins updated and thoroughly reviewing compromised sites for backdoors and reinfection mechanisms. (Sucuri Blog)
What website owners should do
Check your WordPress site immediately if you or a customer sees a Cloudflare verification page that does not behave normally.
Look for:
Plugins you did not install
Plugins with no author or description
Unknown administrator accounts
PHP files inside the uploads folder
Recently modified theme or plugin files
Unfamiliar header, footer, or code snippets
New scheduled tasks or cron jobs
Never follow a verification prompt that asks you to run commands, paste clipboard contents, download software, or disable security tools.
At AIO Web Designs, we help businesses identify WordPress infections, remove malicious code, secure administrative access, and restore affected websites.
π© Contact AIO Web Designs if your website is displaying unusual verification screens, redirects, popups, or unexplained administrator accounts.