Dodgy User Admins created on compromised site
-
HI
So I notice that 1 or 2 usernames have been created on a client site that seems to be compromised.
and wp-adminesr email: [email protected]
Has anyone else come across these usernames as Admin? I have removed them, hopefully the don’t come back in, depending on what other files have been changed.
I’m trying to do a full scan with Wordfence now.
I assume they come in through an old wordpress plugin (I had WP Max Exectuion Plugin ) that I didn’t realise was obsolete. So I have installed Wordfence, scanned, and cleaning up, removed htaccess and added new etc.
I’m assuming people have seen this dodgy usernames previously.
I’ve already updated all plugins, removed the one that was obsolete that I didnt’ know about. Updated WordPress already, and configured Wordfence.
I’m keeping an eye on Live fee also.
Any other suggestions please?
Thanks
- You must be logged in to reply to this topic.