WordPress hacked, Wordfence didn't notify
-
My customer’s site was hacked two days ago. I found this discussion in stackexchange, and the code matches with the code I found in almost every php file: https://security.stackexchange.com/questions/70579/is-this-a-backdoor
I have now cleaned the wordpress with this script: https://gist.github.com/owise1/096c2d31c866eee0adceI also found this article, though the MailPoet plugin WAS NOT INSTALLED in my customers site, nor it has any neighboring sites:
https://blog.sucuri.net/2014/10/wordpress-websites-continue-to-get-hacked-via-mailpoet-plugin-vulnerability.htmlWordfence is on. It didn’t notify me about the changes in files: it seems it halted when it tried to do a scheduled scan. I can see error messages in the log:
[Oct 11 01:22:57:1444515777.112067:1:error] <b>Deprecated</b>: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in <b>…/wp-content/plugins/wordfence/lib/wfDict.php</b> on line <b>1</b>
[Oct 11 01:22:57:1444515777.108687:2:error] Scan terminated with error: We received an empty data response from the Wordfence scanning servers when calling the ‘is_safe_file’ function.The day before WordFence had completed a full scan with no problems to report.
Plugins and wp are up to date. Here are the list of plugins:
Admin Columns
Advanced Custom Fields
Akismet
Antispam Bee
BackWPup
Black Studio TinyMCE Widget
Bunyad Page Builder
Bunyad Shortcodes
Bunyad Widgets
Contact Form 7
Contextual Related Posts
Custom Sidebars
Hello Dolly
Post Thumbnail Editor
Search & Filter
Wordfence Security
WP-PostRatings
Yoast SEO
Theme: Smart-mag (recent security updates done)I’m feeling quite insecure since I don’t now what caused this in the first place. So if anyone has any information about the subject, please let me know.
- The topic ‘WordPress hacked, Wordfence didn't notify’ is closed to new replies.