Title: wp-includes/class.wp.php??
Last modified: June 19, 2017

---

# wp-includes/class.wp.php??

 *  Resolved [spooky1](https://wordpress.org/support/users/spooky1/)
 * (@spooky1)
 * [8 years, 11 months ago](https://wordpress.org/support/topic/wp-includesclass-wp-php/)
 * How can I clear this backdoor? I tried it directly from ftp, but it does not 
   go. What should I do?
 * File appears to be malicious: wp-includes/class.wp.php
    Filename: wp-includes/
   class.wp.php File Type: Not a core, theme or plugin file. Issue First Detected:
   1 hour 34 mins ago. Severity: Critical Status New This file appears to be installed
   by a hacker to perform malicious activity. If you know about this file you can
   choose to ignore it to exclude it from future scans. The text we found in this
   file that matches a known malicious file is: “if ( isset($_REQUEST[‘exec’]) &&
   isset($_REQUEST[‘cmd’]))\x0aDoCmd($_REQUEST[‘cmd’]); else MakeSimpleForm();}?
   >”. The infection type is: Backdoor:PHP/DoCmd.
 * Thank you very much for your help.

Viewing 2 replies - 1 through 2 (of 2 total)

 *  [wfalaa](https://wordpress.org/support/users/wfalaa/)
 * (@wfalaa)
 * [8 years, 11 months ago](https://wordpress.org/support/topic/wp-includesclass-wp-php/#post-9246092)
 * Hi spooky1,
    It could be tricky a little bit, but I highly recommend to calm 
   down and follow these steps precisely “[How to Clean a Hacked WordPress Site using Wordfence](https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/)“,
   then make sure you are applying these security tips mentioned in “[How to Harden Your WordPress Site From Attacks](https://www.wordfence.com/learn/how-to-harden-wordpress-sites/)”
   and “[How to Secure Your WordPress Working Environment](https://www.wordfence.com/learn/how-to-secure-your-wordpress-working-environment/)“.
 * Thanks.
 *  [wfchloe](https://wordpress.org/support/users/wfchloe/)
 * (@wfchloe)
 * [8 years, 10 months ago](https://wordpress.org/support/topic/wp-includesclass-wp-php/#post-9314112)
 * Hello spooky1!
 * I hope we were successful in helping you resolve your issue with Wordfence! Since
   we have not heard back from you in the past 2 weeks I will now be marking this
   support thread as resolved. However, if we still haven’t resolved your issue 
   please reach out to us as we would be more than happy to further assist you!
 * Thanks and have a great day!
    Chloe

Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘wp-includes/class.wp.php??’ is closed to new replies.

 * ![](https://ps.w.org/wordfence/assets/icon.svg?rev=2070865)
 * [Wordfence Security - Firewall, Malware Scan, and Login Security](https://wordpress.org/plugins/wordfence/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/wordfence/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/wordfence/)
 * [Active Topics](https://wordpress.org/support/plugin/wordfence/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/wordfence/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/wordfence/reviews/)

 * 2 replies
 * 3 participants
 * Last reply from: [wfchloe](https://wordpress.org/support/users/wfchloe/)
 * Last activity: [8 years, 10 months ago](https://wordpress.org/support/topic/wp-includesclass-wp-php/#post-9314112)
 * Status: resolved