Security Issue
-
I tried to add my comments on this initially to another post which was expressing the exact same problem that we are having, but you removed my comments and told me to start a new topic for some strange reason. Anyway, here it is.
We are experiencing exactly the same problem as https://ww.wp.xz.cn/support/topic/security-vulnerability-187/. Yesterday we discovered a site had been hacked and the file to allow access to our site had come through the /uploads/cpo_temp folder. We cleaned up the whole system and removed the hacked files, but this morning another exploit had been uploaded to the same folder.
Obviously we are aware that a file being in a folder does not necessarily mean that the plugin related to that folder is vulnerable. However, we host 1 other website that is using UNI CPO, and on running an Imunify AV scan on it this morning, we discovered that that one has also been hacked, and the same file is in the /uploads/cpo_temp. None of the other 50+ sites we are hosting have been hit, and it seems like an unlikely coincidence that the only 2 sites that have been affected are those running UNI CPO, unless there is an issue with the plugin.
I would really appreciate it if you could look into this, and not just remove my message again to try to make it look like there is nothing wrong.
The topic ‘Security Issue’ is closed to new replies.