What is Nostr?
Terence Eden /
npub1lh0…a5ll
2024-07-17 22:30:55

Terence Eden on Nostr: Whoa. I've just been hit with a nasty bit of #WordPress hacking. A plugin which calls ...

Whoa. I've just been hit with a nasty bit of #WordPress hacking.

A plugin which calls itself "Core Functionality" hiding in `/plugins/informative/testplugingodlike.php`

Seems to have added *thousands* of admin users to my sites.

Very odd and concerning. Not using multisite. Each has a different (normal) admin password. Some use MFA.

WTAF??

Author Public Key
npub1lh05slh2nk6h5m3jp7qwtjmrmegtah6nj626g8qdg3a7ds3kg0ss9aa5ll