Hacked plugin v2.1.4
-
Last October 12th we had three websites using this plugin hacked, the user gained access to the admin and installed the plugin wp-files, what gave him/her access to the serve’s subscription filesystem. We replaced the wordpress files three different times and checked all the wp-content files until we found that this plugin was the one hacked. The hacker created two new files with malware:
!…/plugins/amp/vendor/sabberworm/php-css-parser/lib/Sabberworm/CSS/Value/RuleValueLis.php
!…/plugins/amp/vendor/willwashburn/stream/src/Stream/Exception/cc1.phpThese created files into the wp-includes (options.php) filled with malware and edited the .htaccess (and created a new .htaccess inside each one of the folders website) with redirections to other webs.
Please check this plugin for vulnerabilities as this happened in two different servers. We can provide the code of the hacked version of the plugin if needed.
Thanks in advance.
The page I need help with: [log in to see the link]
- The topic ‘Hacked plugin v2.1.4’ is closed to new replies.