wp-file-manager plugin malware ?
-
I have a small site that I administer for a voluntary organisation. It’s a basic site essentially to provide information to people. There is no ecommerce etc on the site. A few months ago my hosting company took the site offline due to malware, following which I took out a monthly subscription for a cleaning tool they supply. Its called SiteLock. This package cleaned the site and now monitors it and does a daily scan. I also read up on improving the site security on the WordPress forums and put other additional steps in place, and this seemed to solve the issue.
However, today the scan detected another piece of malicious code.
“wp-content/plugins/wp-file-manager/lib/codemirror/mode/434.xmlrpc.php
MalwareCleaned Category SubCategory
No CommandControlCoordination FileHackerd(0+0.2+0.2+0.2+0.2+0.2)]”
The previous incidents also seemed to involve the wp-file-manager plugin.
I am a novice at this and would appreciate some advice. Is this a real incident of malicious code, or a false positive ? Is there a vulnerability of the wp-file-manager plug in ?
Andrew
The page I need help with: [log in to see the link]
- The topic ‘wp-file-manager plugin malware ?’ is closed to new replies.