• Yesterday a plugin was installed without my knowledge on my WP site at https://enlightenedschools.com I believe it was malicious and I un-installed it but I am now looking for information on how that could happen so I can be sure I’ve closed the barn door (so to speak).

    Only myself and my partner are admins so there was no un-authorized user. I have been customizing the site’s registration process but I did not find any un-authorized users (definitely no unauthorized admins).

    The unauthorized plugin is Simplelender – it appears to be relatively inactive now. But in the past, people have posted that it is difficult to un-install (when you try to uninstall from the WP dashboard you get an error that you first need to uninstall the premium plugin but there is no premium plugin). I removed it by deleting its files from the server.

    I have been in touch with the company that sells the last plugin I installed but haven’t heard back yet. I don’t want to cause potential damage to their reputation at this point by naming them since I don’t know for certain where it came from. I have inspected the .zip file they provide for installation and it appears to be safe. But I’m not a security expert so I’m not sure what I should be looking for outside the obvious.

    I have Googled on this issue a lot and couldn’t find any articles describing this issue, so any hints on what I should be looking for would be appreciated. I do have iThemesSecurity installed and there was no clues in their logs.

Viewing 5 replies - 1 through 5 (of 5 total)
  • I believe it was malicious and I un-installed it but I am now looking for information on how that could happen so I can be sure I’ve closed the barn door (so to speak).

    I strongly suggest you to install WordFence and run its malicious code scanner. Also, make sure to change all passwords, including FTP, DB, and hosting panel password. If possible, ask your hosting to run a malware scan as well.

    Thread Starter gvenditto

    (@gvenditto)

    Thanks for the suggestion; I ran WordFence and it didn’t find anything.

    Maybe check with you host in case is was installed on their end (has happened to me – though not with a mortgage plugin, that would really be odd). Also may be a good time to change admin passwords, salts and keys.

    Thanks for the suggestion; I ran WordFence and it didn’t find anything.

    That’s great! As mentioned above, change all passwords.

    Thread Starter gvenditto

    (@gvenditto)

    I started searching my database and found that another plugin I had used (and removed) had several database entries for simplelender. In Googling for other mentions of simplelender, I found that other users of this plugin (GravityForms) reported seeing simplelender in their tables. So it seems likely that GravirtyForms was an entry point.

    I’ve removed all trace of both at this point, of course.

Viewing 5 replies - 1 through 5 (of 5 total)

The topic ‘How can plugin install without admin approval?’ is closed to new replies.