Site Hack or Exploit: links to italian PDFs on WP sites
-
I am running WordPress 4.5.3, and the site I am working on has been hacked/exploited. Looking into this I see it affecting other WordPress sites.
The nature of the hack/exploit is to drop in a div with
style="position: absolute; top: -3167px"
and then strangely a link to a PDF document hosted on this or another wordpress server.Here is an example of how it comes out:
[ redacted ]
These hacked links do not appear on every
<a>
tag, but when they do, if the offending</a><a>
tag is removed form the site, the exploit jumps to the next link in the HTML.Other sites affected I have found include:
[ redacted ]
… and probably many more.
`
Strangely these all point to Italian PDFs hosted on the hacked sites.I tried running the Exploit Scanner plug-in but got this error “Searching your filesystem and database for possible exploit code – An error occurred. Please try again later” which makes me nervous!
The theme I am running is Parallax One but the other sites are all on other themes, so I don’t think it’s a theme issue.
Any advice on where this is coming from, how to address it and prevent it in the future would be welcome. Many thanks.
- The topic ‘Site Hack or Exploit: links to italian PDFs on WP sites’ is closed to new replies.