File appears to be malicious: wp-head.php (eval($_POST[)
-
Latest version of WordPress, all themes and plugins are up to date.
Our site was recently attacked, and though we’ve rebuilt it, Wordfence still finds the following file and code as malicious…
File appears to be malicious: wp-head.php
Filename: wp-head.php
File type: Not a core, theme or plugin file.
Issue first detected: 1 hour 39 mins ago.
Severity: Critical
Status: NewThis file appears to be installed by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The text we found in this file that matches a known malicious file is: “eval($_POST[“.
Removing the file breaks the site, removing the code referenced breaks the site.
Thoughts?
- The topic ‘File appears to be malicious: wp-head.php (eval($_POST[)’ is closed to new replies.