Reading view

WordPress site suddenly displays a full-screen iframe pointing to cloudflare-check.net : is this actually related to Cloudflare?

Hi everyone,

I'm trying to understand a strange issue affecting a client's WordPress website:

https://sarltib.fr/

This client is currently in a dispute with their former web agency. I'm supposed to take over the website, but I don't have access to the hosting, WordPress admin, FTP or database yet.

While we're waiting to recover everything from the former provider, this new issue suddenly appeared on the website.

When accessing the site, I get the following error:

“Server IP address could not be found for cloudflare-check.net”

The strange part is that the actual WordPress website is still there and seems to load normally in the background.

In Chrome, when I inspect the page, I can see a full-screen iframe with the title “Security check” displayed on top of the website. If I manually delete this iframe from the DOM using Chrome DevTools, the normal website immediately appears behind it.

In Firefox, I only see the cloudflare-check.net error page.

The WordPress login page at /wp-admin is also still accessible.

Since I don't have access to the website yet, I'm mainly trying to identify what we're dealing with so I can advise the client while the current provider still has control of the hosting.

Has anyone seen this kind of behavior before?

In particular:

  • Could this simply be a DNS configuration issue?
  • Does this look like a compromised WordPress installation / malicious iframe injection?
  • Is cloudflare-check.net actually related to the legitimate Cloudflare service, or is the name just being used to make the page look legitimate?

Thanks for any help or feedback!

submitted by /u/Global-Box-3681
[link] [comments]
  •  
❌