Wordfence reporting malicious uploads, but not stopping them
-
Ever since the last WordPress upgrade, Wordfence keeps reporting that there are malicious but does not seem to stop the attacks anymore:
Below is the last example of the reported malicious uploads: (is backupbuddy creating a backdoor?)
Critical Problems:
* File appears to be malicious: .well-known/index.php
* File appears to be malicious: .well-known/pki-validation/index.php
* File appears to be malicious: cgi-bin/index.php
* File appears to be malicious: index.php
* File appears to be malicious: ip7f4nfb1x_index.php
* File appears to be malicious: wp-config.php
* File appears to be malicious: wp-content/plugins/ultimate-tinymce/artlytny.php
* File appears to be malicious: wp-includes/PHPMailer/hqlndrvc.php
High Severity Problems:
* Unknown file in WordPress core: wp-includes/PHPMailer/hqlndrvc.php
WordPress core file modified: index.php
* Publicly accessible quarantined file found: wp-content/plugins/backupbuddy/destinations/_s3lib2/aws-autoloader.php.suspected
- The topic ‘Wordfence reporting malicious uploads, but not stopping them’ is closed to new replies.