2.3.1 vulnerability
-
My blog appears to have suffered a hack. Details are posted in an entry here.
The hack appears to update wp-includes/default_filters.php to include a backdoor up upload files. It then uploads a file named class-mail.php and also updates classes.php. class-mail.php contains base-64 encoded data containing links and ads which are inserted into the body as hidden text and the page footer.
Another few people appear to have suffered the same:
https://www.howardowens.com/2007/this-blog-was-hacked/
https://www.ads-software.com/support/topic/142586?replies=2I appreciate that a compromised FTP/filesystem access is the most likely cause, and am getting my host to check this out, but thought I would raise it here as well
- The topic ‘2.3.1 vulnerability’ is closed to new replies.