Comment by secretslol

1 day ago

One of my websites was hacked with this, luckily not one with any users at all.

They did this:

- Two admin accounts in the database.

- plugin dir: wp-content/plugins/wp-core with remote command-execution web shell wp-core-[12 random chars].php

- firewall.php backdoor in mu-plugins dir with admin on GET ?sergei

- cache-seo-helper.php backdoor

- fixer.php which renames the wordpress version number to one which is patched.

I have decided to give up on Wordpress.