WordPress hacked – High User ID
-
A WordPress site of mine was hacked twice in the last two days. I am trying to find out where the vulnerability might be.
WordPress is on version 5.8.1 and I use MySQL server version: 5.6.51-91.0 – Percona Server (GPL), Release 91.0, Revision b59139e
The attackers manage to create an administrator user and add content to the home page.
What I noticed, the newly created user has a very high user ID in the database. Currently there are 347 users in the user table, but the newly created user has an ID with 9952! Also the AUTO_INCREMENT value in the database is at this high values.
To me it doesn’t look like normal WordPress functions are used here to create the user, otherwise it would have to be number 348 normally, am I right?
Any clue what kind of attack this could be? SQL Injection?
- The topic ‘WordPress hacked – High User ID’ is closed to new replies.