Theme Twenty-sixteen vulnerability
-
Hello,
My site has been compromised 3 times over the last month. After reviewing the logs, I figured out how it’s being done. The WordPress theme, “twenty-sixteen” has a hole. Where do I report my finding?
First time, I was using theme twenty-fourteen, one version behind. OK, that was my fault. I restored from backup & changed to theme twenty-sixteen.
Second time, I had upgraded to theme twenty-sixteen, removed all plugins. Added iTheme & Loginizer… it was hacked in a 2 days. different exploit than before. blocked malicious IP’s again, but that’s like wackamole – 2 more just pop up..
Third time, changed all directory permissions to 555 files (it’s shared hosting) to 444 or 400 for sensitive files, not just plugins & uploads. i was ready to do all updates manually. it was hacked in a day. Same exploit as in twenty-fourteen. screw this. .
Because it’s on shared hosting I can’t segment my user account owning both the website and file above the public_html folder so I’m going to restore from backup again and install yet another theme.
- The topic ‘Theme Twenty-sixteen vulnerability’ is closed to new replies.