Need fake plugin hack file checked
-
Hi
I woke up this morning finding out that a few hours earlier my site got a new “plugin” installed. If it wasn’t for Sucuri repoting the action i wouldn’t have discovered it, because i didn’t show on the list of plugins.
I have the file and i need someone to tell me what it does.
The problem is that i have a very clean site with only WP, Divi and Sucuri. I had the Customizer Reset plugin from wpzoom. I deleted that just for safety. I didn’t need anymore anyway.
Everything was updated to newest version. There hasn’t been installed other plugins on it. Just a clean site with Divi.
### This is not about that i have been hacked ###
I just need to find out what this “plugin” does, so i can find out how it came onto my site. There has/had to be a crack in the security. Where it came from so the hole can be closed.
So there’s three ways that it can have entered. WordPress 5.9, Divi, (+ the other auto-installed WP themes) and the Cuztomizer Reset plugin.
Of course Sucuri as well. I am in contact with them, and also Elegant Themes.
So what about WordPress, who deals with hacks and security and can take a look at the file and maybe see how it got onto the site, what it exploited – and of course to close the hole if it’s in WordPress itself ?
All the best
Carsten
- The topic ‘Need fake plugin hack file checked’ is closed to new replies.