Just by a chance I have noticed that there is a second administrator on my page with following email address ‘email deleted, don’t post those here‘ with nickname ‘wpcore’ anyone has any idea what this could be please?
I managed to change its email address to my own secondary email, as got scared if I was hacked?! when I googled above .ru email address I found a post about some hack few months back, so I panicked.
Ideally I would like to remove second admin completely, but there is no option to delete that user?! Or am I missing something?
Does anyone have maybe email of phone to contact www.remarpro.com direct to get help?
Thank you!
Petra
]]> [01-Nov-2022 13:52:27 UTC] PHP Warning: Unknown user in ./public_html/wp-content/plugins/jetpack/sal/class.json-api-post-base.php on line 782
I looked in the file around line 782 and found this:
$user = get_user_by( 'id', $this->post->post_author );
if ( ! $user || is_wp_error( $user ) ) {
trigger_error( 'Unknown user', E_USER_WARNING ); // phpcs:ignore WordPress.PHP.DevelopmentFunctions.error_log_trigger_error
What was the Unknown User doing?
]]>I’ve updated WP and PHP and disable themes and plugins and checked the admin rights in phpmyadmin.
however I’ve noticed that I have an unknown user account that cannot be deleted, I’ve tried via the dashboard and via relevant tables in phpmyadmin. It seems to be rewriting itself back in to the site no matter what I do. Have I been hacked?
Each time I view the user I get a different message relating to code on the following page, this is the current message
Notice: Undefined offset: 0 in /home/hp3-linc8-nfs2-y/720/2185720/user/htdocs/wp-includes/class-wp-query.php on line 3284
I’ve done a word fence scan and tried to delete old PHP files that look as if they are preventing verified admins from accessing plugins and themes and other updates, but nothing has worked so far.
Does this seem like a site hack? if so what is the best way to get the site repaired? is it worth the several hundred dollars to get Wordfence to look at it, or would I just be best going for a fresh instal and rebuild of my site.
Please help as I”m tearing my hair out here!
Thanks
]]>I am the owner of a www.remarpro.com website. Recently we found a very odd-looking username and email with “Customer” status.
The Username is . The email is @dmail1.net. When doing a Google search of the entire email, nothing comes up. When doing a Google search of just dmail1.net it appears to be a real email provider.
When doing a Google search of @dmail1.net, a lot of links come up with words like spam, abuse report, etc.
When doing an email check on cleantalk.org, the results say it’s a real email, and check-mail.org lists this domain as Temporary/Disposable.
Nothing that looks good.
Anyway when we went to delete the @dmail1.net user, the next page asks ‘What should be done with content owned by this user?’ and you must then select one of two options: 1, Delete all Content. Or 2, Attribute all content to: with a text box next to it. That’s when we noticed that the text box has the username of one of our authentic customers in it. ???
We didn’t delete the email and starting looking around a little further. We realized if we click Delete under many, but not all of, the real users that the “Attributed to” text box is auto-populated with the @dmail1.net email – including three of the Administrator accounts. The whole thing is really weird. We’re unsure why only some Users are linked but not all.
We still haven’t deleted anything and just want to make sure that we don’t crash something with these linked user accounts. That probably wouldn’t happen but figured we should research this first and hopefully get some support.
Also interesting to note, we’ve noticed recently that the website began showing ads and have been unsure what’s causing it or how to get rid of them and are suspecting this implanted “User” may be the source.
Any insight and support would be very much appreciated! Thank you for your time.
]]>I had a strange thing happen today while updating plugins and WP core on my site. I had deleted all old plugins and installed All in one WP Security. Everything is up to date and working well.
I was also logged in to my cPanel, deleting old files etc. so was working in browser tabs. (Firefox)) Within a half hour When I was in my WP tab I had a notification from aiowp that there were TWO Users currently logged in!
NO! it should only be me! But the 2nd user had the same user name. Both were my own WP user-name (it is NOT admin). However the IP was different, in fact it was the ip of my website. I was able to force the second user to log out immediately and then I logged out myself and cleared the cache and cookies.
I asked my host to scan the site for unusual activity and signs of malware but they found nothing. I am grateful for the warning but I am still worried.
I am hoping that this was strange behaviour by AIOWP and maybe there were not two people logged in.
So my Question is this.
Can someone log in to my website using my own website server’s IP and has anyone heard of this happening before? If so, what can I do to stop it happening again?
Thanks, I hope this is not too confusing.
I have ticked, ‘This is not a support question’ because I think it is maybe only asking for an opinion – I did not want to imply there is anything wrong with the plugin, but I would like to know whether it is a dangerous situation or not.
]]>Other analytic tools show page visits and the pro plugin does not
i am using thrive themes and digimember
thank you in advance
PS: already wrote your agency support but here is the only support where i can not show any pictures…
]]>Failed to get data. Error:
Start tag expected, ‘<‘ not found
Data returned by Google:
Unknown user.
I went into Photonics Helpers for Picasa and it says “no albums found.” I tried setting up the Google photos section and the Helper for Google photos can’t find the albums there either.
I went to one of your documentation pages (https://aquoid.com/plugins/photonic/picasa/picasa-albums/) and all your Picasa galleries are showing the same “failed to get data” errors instead of the galleries in Chrome and Firefox.
Have martians taken over the plugin? Has my computer gone crazy? I have no idea what’s going wrong when they were working fine earlier today.
]]>According to the Stream logs, yesterday an unknown user with ID 0, deleted almost all the widgets we had in one of our websites (more than 20, all in less than one second). Ip 207.46.13.117 which seems to be a Microsoft bingbot ip.
We have the WordPress pretty secured. So I suspect the editing may have been done directly in the database through a vulnerability in the hosting. But I can’t be sure.
Since you know more about how your plugin logs events. Do you think that possible?
thank you
]]>I’m worried this is some hacker abusing my site. I don’t see any new posts or changes to the site, but I’m freaking out over what might be done. Any suggestions or helpful advice? Since the name disappears under users I cannot actually delete the user.
]]>