Site Constantly Being Hacked
-
Been using this plugin on a few sites. Love it. It’s the best stat plugin for WordPress (tried most of them). But for months, the sites have been getting hacked every few days. WP and the plugin are all updated.
The hacks are crazy scripts being injected in the header.php file. You know you’ve been hacked because there is a gap at the top of your homepage, almost as if the CSS got messed up. Then you go into header.php where you will find a bunch of nonsense between <script></script> tags. One of the hacks was so bad that it was redirecting all visitors to porn sites.
Then saw this: https://www.livehacking.com/2015/02/25/wp-slimstat-vulnerability/
And other articles. I have deleted this plugin and no more hacks so far. It’s very upsetting if this plugin is being used to give access to hackers.
Definitely recommended not to use this plugin for now and would like to hear from the author about the articles and experience above.
- The topic ‘Site Constantly Being Hacked’ is closed to new replies.