Plugin generates spam posts when installed
-
Hi,
I installed your free plugin a few days ago in our corporate page because we are looking for an editorial content calendar plugin and wanted to test yours out. I received an email from our Google Search Console’s account telling us our site had pages marked with the hacked site type “URL injection” in the following urls:
https://pibeca.com/dissertation-assistance-services
https://pibeca.com/umi-dissertation-services
https://pibeca.com/i-write-my-dissertation-in-a-week
https://pibeca.com/phd-no-dissertation
https://pibeca.com/accounting-dissertation-help
https://pibeca.com/dissertations-to-buyThe most alarming thing after this is that when we try to access one of these pages, we are redirected (using javascript on the body of the post – location.replace() )to the following website: https://superbpaper.com/?cid=2626
We have thoroughly reviewed the website, the theme we are using and other plugins installed and found out that these pages only show up when your plugin is installed. If we uninstall it, these urls are redirected to our custom 404 page (as they should be).
I don’t think this behavior of the plugin is right (not even for a free plugin, although it should be advertised somewhere before the user installs it). I would like to know if this is a known behaviour, if it is some remanent code from the last update, or if it has been hacked.
- The topic ‘Plugin generates spam posts when installed’ is closed to new replies.