Scans not detecting phishing files in wp core
-
I have a customer that has been hacked twice in the last 30 days, all plugins are pretty common plugins with no reports of vulnerabilities and up to date as is wf but they keep getting suspended due to phishing files located inside the wp installation. I can’t figure out how they are hacking the site unless they have direct server access somehow???
This time it was an extra folder inside the /wp-includes/js/ folder. I ran a wf scan without removing the files and expected wf to detect these files but it didn’t. Is this normal? Will the scans only detect if core files have changed but not the existence of new files in the folder structure?
All file permissions are pretty standard, 755, 644.
- The topic ‘Scans not detecting phishing files in wp core’ is closed to new replies.