Does anyone have idea wtf is this?

Did you have Wordfence or similar plugin installed? If not, please add. Go to Sucuri site check tool and find the location where code is injected. Removed the code. It will be fixed. Good luck.
Found it, I tried deactivating plugins one by one and it was wprocket. I totally forgot I downloaded it here on BHW.

It was a few months ago. I installed the better history extension to check my old history faster. And found the thread where I downloaded it.

Here it is: https://www.blackhatworld.com/seo/g...gin-latest-version-3-9.1329152/#post-14527365

Lesson learned. No more fucking free plugins.
 
Last edited:
Thanks. I will install it right away.
Your're welcome the Indian guy behind it highly intelligent he can easy if you buy the licence unless it changes since I got it appsumo fix it for you once you buy the licence.
 
This block appeared in my wordpress dashboard. I have no idea since when it is there, I noticed only now.

View attachment 185848

This is what google returned when I googled the title.

View attachment 185849

I have only trusted 5-6 plugins and free Astra downloaded from the official page. I'm not located in an Arabic speaking country or near.

Should I be worried?
It looks like somebody inserted a code and hacked your website through brute force attack or by other ways. If you have shared admins whose passwords are sensitive, then I recommend you to immediately update the password to strong ones also install WordPress security plugins for your website. And meanwhile, you should report to GSC about your website, as it's going to effect in SEO.
 
probably cause of some plugin you installed lately
 
It maybe not that WProcket plugin, but I can't sure.

I also downloaded nulled WProcket on here (another thread), but seems it didn't cause any havoc... yet ....
 
That from a trusted person on here that wp download I'll be very surprised was that plugin or from here.

He only provides downloads with scan checked wp plugins.
 
Sorry that this happened to you but reality is CMS's, cPanel's or WHM's get hacked all the time. The shit is just straight up garbage and most of the time misconfigured to make it even worse.
 
Found it, I tried deactivating plugins one by one and it was wprocket. I totally forgot I downloaded it here on BHW.

It was a few months ago. I installed the better history extension to check my old history faster. And found the thread where I downloaded it.

Here it is: https://www.blackhatworld.com/seo/g...gin-latest-version-3-9.1329152/#post-14527365

Lesson learned. No more fucking free plugins.
:eek:
Well, I would still recommend in purging the entire database and stating afresh.
Never know what kind of codes or backdoors they added to your SQLdatabase, other files and any other vulnerables exploits that could be around.
Rule of thumb for me on nulled stuff, if it isn't @Festinger it's not worth the risk

You should always have a plugin or equivalent to stop bruteforce, which can be in a form of firewall or even something as simple as 2FA
 
That from a trusted person on here that wp download I'll be very surprised was that plugin or from here.

He only provides downloads with scan checked wp plugins.
Maybe the guy who shared also wasn't aware of that. Virustotal did not track anything when I rerun the test on Saturday, neither did Wordfence. But the ad feed was clearly being caused by the plugin, that's for sure.
 
How I wish hackers can just leave us WordPressers alone. We are just trying to earn an honest living and occassionally just pop up and ruin things by bringing down our sites. At one point I had no income for an entire month because my money site was hacked in a way that I lost everything and had to build my site from scratch. I was jsut starting out at the time so I was not aware that you can actually recover the site without having to delete it entirely.
 
Back
Top