Hello, I have a client who has a Wordpress site built last year. However, due to lack of security protocol, we believed that the site has been compromised and we can't seem to find the cause of the problems. Some problems we faced: 1) Design of the site changes even after we update it to the latest version 2) Wordpress users were created automatically even after removal manually 3) Server will get uploaded with adult content after a while I am currently seeking any professional expert that is keen to look into the problem. Kindly pm me for more information. Thank you.
In many such cases, the best option is to install a fresh WP and copy the posts from the old installation.
You can try the following: Remove all users that you think are hackers Change all the password you have used on the site, including web hosting panel password Change the theme to genuine theme Uninstall all unnecessary plugins Install security plugin like WordFence Monitor your site activity via web host, user logs etc.. Use Sucuri.net to check whether your website is clean
Doing a clean install of Wordpress and using the same database, but after checking the database for iframes and javascript embedded in content.
It seems that it's an issue that involves malware. Have contacted your provider to run a malware scan? Some providers offer malware scan for free. If you need guidance/assistance on this, you may contact us at https://www.mechanicweb.com
You can visit http://www.google.com/safebrowsing/diagnostic?site=domain name. It might show a warning if there is a malware threat. You can try changing passwords maybe. You can have some structural problems with the sire also.
yeah, i had the same problem. You shoul do all what Mike said, plus you can configure some wp plugins to get better security. For example to protect from brute force just configure All In One WP Security & Firewall plugin to hide admin or use bunch of other plugins to prevent from xss
try to check manually log, its sounds like some one get upload shell on your server and get your server backdoor , check server logfile , it will help you to identify activity,