AI Search
Classic Search
 Search Phrase:
 Search Type:
Advanced search options
 Search in Forums:
 Search in date period:

 Sort Search Results by:

AI Assistant
Notifications
Clear all

[Closed] Forum - potentially hacked

3 Posts
3 Users
1 Reactions
2,580 Views
Posts: 1
Topic starter
Translate
English
Spanish
French
German
Italian
Portuguese
Russian
Chinese
Japanese
Korean
Arabic
Hindi
Dutch
Polish
Turkish
Vietnamese
Thai
Swedish
Danish
Finnish
Norwegian
Czech
Hungarian
Romanian
Greek
Hebrew
Indonesian
Malay
Ukrainian
Bulgarian
Croatian
Slovak
Slovenian
Serbian
Lithuanian
Latvian
Estonian
(@james_s)
New Member
Joined: 5 years ago
[#16425]

Hello,

We added WP Foro to our wordpress site around 6 weeks ago. A couple of days ago, someone was able to inject some code into an admin's post. The code was malicious but, fortunately, because it was injected into a text post, the script was not executed.

Our security settings and permissions are solid, we've had no issues until now. Only admin users have the ability to add/edit forum topics, so it seems like we may have been hacked.

I don't know if the forum plugin has been hacked, or if our site has been hacked elsewhere. Can anyone provide a recommendation for how to ensure that this doesn't happen again? 

Thanks,

James


Topic Tags
2 Replies
dimalifragis
Posts: 2600
Translate
English
Spanish
French
German
Italian
Portuguese
Russian
Chinese
Japanese
Korean
Arabic
Hindi
Dutch
Polish
Turkish
Vietnamese
Thai
Swedish
Danish
Finnish
Norwegian
Czech
Hungarian
Romanian
Greek
Hebrew
Indonesian
Malay
Ukrainian
Bulgarian
Croatian
Slovak
Slovenian
Serbian
Lithuanian
Latvian
Estonian
(@dimalifragis)
Famed Member
Joined: 6 years ago

Probably your site is hacked (?) via some other point (not wpForo), a plugin or a theme or security issues you may have.

Impossible to tell.

You MUST find how this was done, otherwise you will be hacked again. And of cource you must clean whatever was infected.

Google the script and see what it does and what you must clean.

Install a security plugin. I HIGHLY recommend

https://wordpress.org/plugins/ninjafirewall/

in full waf mode.

Check your hosting security.


Tutrix
Posts: 1519
Translate
English
Spanish
French
German
Italian
Portuguese
Russian
Chinese
Japanese
Korean
Arabic
Hindi
Dutch
Polish
Turkish
Vietnamese
Thai
Swedish
Danish
Finnish
Norwegian
Czech
Hungarian
Romanian
Greek
Hebrew
Indonesian
Malay
Ukrainian
Bulgarian
Croatian
Slovak
Slovenian
Serbian
Lithuanian
Latvian
Estonian
(@tutrix)
Noble Member
Joined: 6 years ago

@james_s

you can check your page here https://sitecheck.sucuri.net/


Share: