Website Comprimised
-
Good Afternoon,
So I logged into our website to find that Wordfence had been deactivated. I re-activated it, and started a scan and it found these files:
vars.php – Modified Official File
skirt.php
Jcrop.php
class.wp-includes.php
wp-widgets.phpI have cleaned up the website by FTP, so I am fine for now, but I am at a loss as to why my website is compromised. There are only 2 users, each with strong passwords, along with our database with a strong password, and our file permissions set to 644 through FTP.
Is there a vulnerability within wordfence lately?
There doesn’t appear to be any users created out of the blue, and only 1 of the official users logged in, and last login was 9/12. The files I found showed they were added 9/17.
The topic ‘Website Comprimised’ is closed to new replies.