Plugin hacked?
-
A wordpress site I administer makes use of the insert pages plugin to pull content from other pages onto the front page, using the page slug method.
Yesterday one of the insert pages shortcodes, instead of displaying the content from a page, showed bogus content from a Chinese source.
I’ve pulled the shortcodes from the front page and set up a test page to recreate the issue (via WP’s preview). Looking at the rendered code, it seems the shortcode has been hijacked somehow – instead of displaying the intended page’s ID, a different page ID is shown. There’s no such page ID shown on the WP backend.
I’m not sure what might have happened here. From my limited knowledge, it seems that someone’s created a bogus page on the database, and then hijacked the shortcode to display that page instead. Is this a likely explanation? A Wordfence scan reports no problems on the site, and there have been no logins that are unaccounted for.
- The topic ‘Plugin hacked?’ is closed to new replies.