• A new user with admin rights keeps appearing on my user list. I have not added it and when I delete it another with a similar name appears. The email address is “.ru” as is the IP it comes from. I’ve added all the security I can think of but cannot see how this is happening. Any suggestions please.
    Bob

    The page I need help with: [log in to see the link]

Viewing 5 replies - 1 through 5 (of 5 total)
  • Bob,

    Contact your webhost right away for assistance. If you have a Managed WordPress Host like SIteGround, Kinsta, or WP Engine, they can help you top this from happening.

    Meanwhile, update your WordPress to the latest version, also update your Theme and plugins to the latest versions.

    Lastly, create a NEW user with administrator rights with a STRONG password, and delete all other users, including your current user.

    You did not give us a link to your website, but making sure it has a SSL installed for the HTTPS protocol is important too. The hosts I listed above provide FREE & EASY ways to achieve that level of security, and provide security measures in their hosting environments.

    If you are on a EIG owned hosting provider, you may want to install something like iThemes, a free security plugin.

    Hope something I said was helpful!

    Take care,
    JD

    Thread Starter crawlerm

    (@crawlerm)

    Thanks JD,it’s [ redundant link removed ] is up to date and has SSL , Wordfence and ithemes security. I’ll get in touch with hosting service and try to sort the out-dated theme and plugins.

    • This reply was modified 7 years, 7 months ago by Jan Dembowski.
    Moderator Jan Dembowski

    (@jdembowski)

    Forum Moderator and Brute Squad

    Moved to Fixing WordPress, this is not an Everything else WordPress topic.

    Sounds good. Hope they help you sort it out. Take care.

    Martin

    (@whocares2018)

    There was a security issue a few days ago in the WP GPDR plugin, allowing someone introducing a new user (admin level) in your site. You should have had an email from your site telling you so.

    rollback from a previous backup, login and download the latest plugin updates.

    Installing the ninja firewall will help preventing a hack again, since wordfence did NOT prevent this hack from happening…

Viewing 5 replies - 1 through 5 (of 5 total)

The topic ‘Admin user being added by hacker’ is closed to new replies.