6 sites have added administrator level users added
-
This morning I woke up to 6 of my 8 sites that have one or more administrator level users added (not by me). Most of these sites had WordFence updated to the latest version but two were on the last version.
I have WordFence options ticked that anyone that tries to login with a fake administrator username will be blocked (and after 3 attempts locked out for 5 days). Most of these sites do not use admin as the administrator login username.
It might be a WordPress vulnerability because on some of these fake administrator users there was no email address or they had the identical email address to my actual administrator login – this is not supposed to be possible with WordPress.
It looks like the hacker changed some WP core files on some of the sites – I’m still scanning to find out how extensive the damage was.
Although I appreciate that WordFence let me know about the “successful” logins so that I could quickly get in and clean the sites I don’t understand how these logins were possible with WordFence activated.
Any suggestions to help keep this from happening again will be appreciated.
- The topic ‘6 sites have added administrator level users added’ is closed to new replies.