• My WordPress sites got hacked. Someone managed to inject a script into the header.php file of my theme. This would try to bring up a popup from another site and distribute malware.

    I have since updated to the latest version of WordPress, but I need to know if 1.This will happen again and 2.How it happened. Several of our WordPress sites were affected, each with different themes, but no one gained access to the server, so it had to be a WordPress exploit.

    I found this when I went to one of our sites and was greeted by a big red warning from Google about this site having malware in it. Had to go through a whole review process with them.

    Is anyone familiar with this attack? Surely we weren’t the only ones.

Viewing 4 replies - 1 through 4 (of 4 total)
Viewing 4 replies - 1 through 4 (of 4 total)
  • The topic ‘WordPress Sites Hacked – XSS in Theme Header’ is closed to new replies.