Allows an attack?
-
I installed this plugin on 3 of 15 sites (no other site changes) and very shortly afterwards those sites experienced a new signup from a .ru email address (despite new user reg explicitly being disabled). I only know this because wordfence notified me of the registration. When I checked it out, all the headers were being redirected to getmyfreetraffic.com as well as submission for the login form…
Looking through my notes, the same thing happened on a different site about 6 months ago when I installed this plugin (among other things then).
Restoring the DB to it’s state from before the sign up and removing the account fixed the hack.
I’m 99% sure this plugin was the vector in both cases… Given it’s install based, I’m surprised…. Is this intentional or an accidental issue?
The topic ‘Allows an attack?’ is closed to new replies.