Title: Possible exploit
Last modified: November 3, 2019

---

# Possible exploit

 *  Resolved [CheechRockwizard](https://wordpress.org/support/users/cheechrockwizard/)
 * (@cheechrockwizard)
 * [6 years, 6 months ago](https://wordpress.org/support/topic/possible-exploit-3/)
 * Just a heads-up for other users of this plugin and the developers.
 * In my Google Analytics reports, I’d recently noticed lots (thousands) of requests
   to URLs with these three sets of odd parameters:
    /products/product-name/????/
   user-new.php= /products/product-name/????/plugins.php= /products/product-name/????/
   theme-editor.php=
 * On further investigation, the page for the product-name in question never completely
   loaded. On stopping the load, Chrome was asking if I wanted to save a password
   for a user named [woosales_wordpress@gmails.com](https://wordpress.org/support/topic/possible-exploit-3/woosales_wordpress@gmails.com?output_format=md).
 * Also, during my investigations, I did on occasion receive “429 Too Many Requests”
   errors from Apache.
 * I noticed the three products in question had been added to a newly created demo
   PPOM category and then that two additional Administrator WP accounts had been
   created. This new PPOM category was running an external JavaScript file. Unfortunately,
   I no longer have the URL as I just cleaned it out.
 * I removed the Administrators and the PPOM groups and updated from 18.4 to 18.6,
   which has hopefully resolved the exploit although I’ve not read the release notes.
   I’ll be keeping a close eye for similar activity over the coming weeks.
 * If the developers are unaware of this they may want to look into it.

Viewing 4 replies - 1 through 4 (of 4 total)

 *  [N-Media](https://wordpress.org/support/users/nmedia/)
 * (@nmedia)
 * [6 years, 6 months ago](https://wordpress.org/support/topic/possible-exploit-3/#post-12094571)
 * Hi [@cheechrockwizard](https://wordpress.org/support/users/cheechrockwizard/),
 * Thanks for sharing these details but didn’t face or reported an issue like this.
   Every of the our inputs is sanitized and scripts are properly enqueued. If you
   still found any issue please let me know, I will see this ASAP.
 *  [Gal Baras](https://wordpress.org/support/users/galbaras/)
 * (@galbaras)
 * [6 years, 6 months ago](https://wordpress.org/support/topic/possible-exploit-3/#post-12096767)
 * [@cheechrockwizard](https://wordpress.org/support/users/cheechrockwizard/) it
   looks like you might need more secure hosting or a good security plugin (iThemes
   Security or Wordfence)
 *  Thread Starter [CheechRockwizard](https://wordpress.org/support/users/cheechrockwizard/)
 * (@cheechrockwizard)
 * [6 years, 6 months ago](https://wordpress.org/support/topic/possible-exploit-3/#post-12103879)
 * So you _did_ know about it…
 * “This issue was older version but current version doesn’t have bad script.”
 * [https://wordpress.org/support/topic/admin-user-creating-attack-4/](https://wordpress.org/support/topic/admin-user-creating-attack-4/)
 * Hopefully, this is fixed in 18.6 as I haven’t so far seen a recurrence of the
   issue.
 * And thanks, Gal, but it doesn’t seem WordFence picked up on this issue either,
   nor did iThemes Security as I’m running that already!
 *  [Gal Baras](https://wordpress.org/support/users/galbaras/)
 * (@galbaras)
 * [6 years, 6 months ago](https://wordpress.org/support/topic/possible-exploit-3/#post-12104879)
 * [@cheechrockwizard](https://wordpress.org/support/users/cheechrockwizard/) security
   issues are best kept hush hush, and on 18.5, I don’t see external scripts being
   loaded.
 * BTW, it seems like your site was not letting anyone in. Getting too many connections
   probably just means you were under a serious attack and your server quota was
   maxed out.
 * Still, to be sure, can you provide a way to replicate the problem, so that it
   can be tested properly?

Viewing 4 replies - 1 through 4 (of 4 total)

The topic ‘Possible exploit’ is closed to new replies.

 * ![](https://ps.w.org/woocommerce-product-addon/assets/icon-256x256.gif?rev=3186763)
 * [PPOM - Product Addons & Custom Fields for WooCommerce](https://wordpress.org/plugins/woocommerce-product-addon/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/woocommerce-product-addon/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/woocommerce-product-addon/)
 * [Active Topics](https://wordpress.org/support/plugin/woocommerce-product-addon/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/woocommerce-product-addon/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/woocommerce-product-addon/reviews/)

 * 4 replies
 * 3 participants
 * Last reply from: [Gal Baras](https://wordpress.org/support/users/galbaras/)
 * Last activity: [6 years, 6 months ago](https://wordpress.org/support/topic/possible-exploit-3/#post-12104879)
 * Status: resolved