Unauthorised Login Attempts Despite Securing Website
-
I’m not sure on the *exact* version of WP as it’s just happened on a couple of older clients’ sites.
This has happened several times however. On websites where I’ve:
– Installed Wordfence plugin to block brute force attacks
– Changed username to something other than ‘admin’
– Disabled template editing
– Disabled directory browsingYet somehow, every now and then someone is still gaining access to the WP backend. I get an email from Wordfence saying that someone with username ‘admin’ has just logged in… how do they do that when there isn’t even a user called ‘admin’ in the first place???
Not only that, but on one of the sites my own admin account (with a diff username) has been removed. So now there is only one editor account (my client’s login) however it has had its username changed to ‘admin’ and the password changed also.
Could this be down to out of date plugins? Also, it’s just happened to two websites within the same 10 minutes, and they’re both hosted on the same server. Could this be something to do with the hosting itself?
- The topic ‘Unauthorised Login Attempts Despite Securing Website’ is closed to new replies.