What is SQL injection?
A database is the place where your site stores its content, such as posts and user names. SQL is the language used to talk to a database. In an SQL injection attack, a bad person types harmful SQL into a form or a web address. If the site is not careful, it runs that code. The attacker may then read, change or delete your data.
Imagine a librarian who follows every note slipped under the door. That is a site open to injection.
Ways to protect your site
- Take a backup first. Save your files and database before you change anything.
- Update everything. In the WordPress dashboard, open Dashboard then Updates. Update WordPress, themes and plugins. Most attacks use old, known bugs.
- Delete what you do not use. Remove unused plugins and themes in Plugins and Appearance.
- Use trusted sources. Install plugins and themes from the official WordPress directory or known makers. Avoid pirated "free" paid themes. They often hide bad code.
- Install a security plugin. Many security plugins include a firewall. A firewall is a guard that blocks bad requests before they reach your site.
- Use strong passwords. Use long, different passwords for WordPress, cPanel and the database.
- Limit user power. Give people the lowest role they need. Few users should be Administrator.
- Change the database prefix. By default tables start with
wp_. A custom prefix makes guessing a little harder. Only do this on a new site, or with expert help, as it can break an old one. - Keep file permissions correct. Folders are usually 755 and files 644. Do not set anything to 777.
- Turn on a server firewall. ModSecurity is a server firewall that blocks many injection tries. Ask Hostvento support if it is on for your plan.
- Check your logs. Strange web addresses with words like
UNIONorSELECTcan signal an attack.
Tip: If you think your site was hacked, change all passwords at once and open a ticket at https://secure.hostvento.com/submitticket.php.
Quick recap
- SQL injection tricks a site into running harmful database commands.
- Update WordPress, themes and plugins often.
- Remove unused add-ons and use trusted sources only.
- Use a firewall, strong passwords and careful user roles.
- Keep regular backups.