WordPress admin username changed to html404
-
Posting this as a public service alert to the Wordfence community. For the general community I have started a similar thread in the ‘Everything else WordPress’ forum here: wordpress-admin-username-changed-to-html404.
My client’s admin account was hacked this morning, admin user account name was replaced with ‘html404’
I’m still in the process of conducting a forensic analysis on the website access logs. Will post findings on the community thread (see above link).
Website is running a selfhosted version of WordPress, 4.9.2. Running Wordfence version 6.3.22.
I immediately:
– logged in and confirmed user html404 appeared in user list.
– opened the html404 user profile in the profile editor
– logged user out of all sessions
– changed the user email and password
– created another admin profile to replace the hacked profile
– deleted the hacked profile, attributing all its content to the new
admin profileThanks and blessings to the Wordfence team for their awesome plugin which alerted me to this issue. You folks rock!!! ????
- The topic ‘WordPress admin username changed to html404’ is closed to new replies.