Title: Malware in woocommerce-add-ajax-admin-dev
Last modified: December 4, 2020

---

# Malware in woocommerce-add-ajax-admin-dev

 *  [captainswallow](https://wordpress.org/support/users/captainswallow/)
 * (@captainswallow)
 * [5 years, 4 months ago](https://wordpress.org/support/topic/malware-in-woocommerce-add-ajax-admin-dev/)
 * This alleged plugin was recently detected in one of the sites I manage “woocommerce-
   add-ajax-admin-dev” – I say “detected”, but only after a rogue admin account 
   was somehow created and the site locked down and scanned (even though it’s regularily
   scanned with Sucuri, among other safety measures).
    This was NOT uploaded to 
   the best of my knowledge, though the server claims it was uploaded in March of
   this year (of course). It does not appear to exist in the WP repository, nor 
   anywhere else – neither does the alleged developer, “Grem Lucci”.
 * Following is information from the file:
    * The plugin’s add functions to ajax
   help admin * * [@since](https://wordpress.org/support/users/since/) 2.4.2 * [@package](https://wordpress.org/support/users/package/)
   WooCommAjaxHelp * * @waddtocarts-plugin * Plugin Name: WooCommerce to add ajax
   help * Description: All add to carts woocommerce * Version: 2.4.2 * Author: Grem
   Lucci * License: GPL-2.0+ * License URI: [http://www.gnu.org/licenses/gpl-2.0.txt](http://www.gnu.org/licenses/gpl-2.0.txt)*
   Text Domain: woocomm-ajax-help * Domain Path: /languages * WC tested up to: 4.0

Viewing 1 replies (of 1 total)

 *  Moderator [Ipstenu (Mika Epstein)](https://wordpress.org/support/users/ipstenu/)
 * (@ipstenu)
 * 🏳️‍🌈 Advisor and Activist
 * [5 years, 4 months ago](https://wordpress.org/support/topic/malware-in-woocommerce-add-ajax-admin-dev/#post-13747473)
 * Sadly this generally means you have been hacked and the malicious actor dropped
   a file/plugin that LOOKS like another one in your site 🙁 Since you’re already
   paying Sucuri, you may want to ask them to do a full scan of your whole site (
   esp the database). The odds are something on there is vulnerable.
 * To explain this part:
 * > This was NOT uploaded to the best of my knowledge, though the server claims
   > it was uploaded in March of this year (of course).
 * So that means that Sucuri didn’t spot anything bad in the file at the time, and
   gives you a point in time as to when there WAS a vulnerability. But March was
   a million years ago so it’s not going to be super helpful here.

Viewing 1 replies (of 1 total)

The topic ‘Malware in woocommerce-add-ajax-admin-dev’ is closed to new replies.

 * In: [Everything else WordPress](https://wordpress.org/support/forum/miscellaneous/)
 * 1 reply
 * 2 participants
 * Last reply from: [Ipstenu (Mika Epstein)](https://wordpress.org/support/users/ipstenu/)
 * Last activity: [5 years, 4 months ago](https://wordpress.org/support/topic/malware-in-woocommerce-add-ajax-admin-dev/#post-13747473)
 * Status: not resolved

## Topics

### Topics with no replies

### Non-support topics

### Resolved topics

### Unresolved topics

### All topics
