Wordpress malware on 15 sites, can this be cross-domain infection?

supereek

Power Member
Joined
Dec 28, 2012
Messages
727
Reaction score
298
Hi,

I found malware today on my sites (wp vdc). They are all in the same DirectAdmin account but run as separate sites.
Luckily I have dealt with this malware before, so I knew what code to remove and what files to clean it up.

The strange thing is this:
- All sites run paid themeforest themes and plugins (NO cracked/nulled stuff anywhere)
- Most of them were frequently updated
- All have strong passwords and anti-bruteforce plugins like Loginizer with strict whitelisting rules
- All have altered login paths by 'wps hide login' so no standard /wp-login/ or /wp-admin/

So I can't figure out how this could have happened... As far as I know the files of 1 WP instance cannot access the other website's roots as they have no path privileges to it. Or am I wrong here?

I have set some additional security plugins now like Wordfence, but they make the sites slower in my opinion.

Any ideas how this could've come and if the theory above is plausible? o_O
 
Happened to me to. Infected all my sites (Bluehost). Found someone good on Upwork who handled it all if you need help.
 
I'm not knowledgeable to this? Can you help me understand please?
 
Strange, but there must be some nulled/cracked plugin or theme used in past.
Do one thing, install a plugin named gotmls update the definition of the plugin and scan your sites.
It will find the infected files and you will get pretty much an idea how it got infected.
 
Could be issue with direct admin.

Contact support and ask them to check complete logs.

They can tell how those were uploaded.
 
Probably a hosting issue. I have experience with malware on wordpress sites in hostgator. I would take down the sites and clean them only to be affected again. Then came to know from other owners that they were experiencing same issue. Hackers got into hosgator server and injected javascript at the top of wordpress core filed. Lost patience after 4th time and left hostgator for good. Which version of wordpress are you running?
 
That might happen with any hosting provider. I suppose you as end user might not be aware of all details. That would be better to ask support to restore your WP sites from backups (make sure that date is before the date of infection) .
Change passwords and ask for additional protection on this matter from your web hosting provider.
 
That might happen with any hosting provider. I suppose you as end user might not be aware of all details. That would be better to ask support to restore your WP sites from backups (make sure that date is before the date of infection) .
Change passwords and ask for additional protection on this matter from your web hosting provider.

I had the same problem with 24/7 hosting... haven't had an infected website since I left them last year
 
Back
Top