Reading view

URGENT!!! - Wordpress hacked and findings

Hi,

We have been dealing with a pretty bad hacking attempt on a wordpress site.
I cant revel what site it is, but they managed to get in when Elementor was vulnerable in the last two weeks.

What they did.

Installed "User editor" and changed a few customer accounts to have full admin capabilities.
Installed GTM4WP plugin and the GTM-T77JRSFZ, this was only picked up from doing a pingdom/pagespeed test and the JS payload was there. This injected RIVBYTE.COM into the site

/019 this is the malware file, which is a CC stealer.
Wordfence nor Immunify picked this up.

After I spotted the odd GTM in pingdom have I managed to back trace the hack.

I have WP ACTIVITY LOG from melapress which was logging everything, and using CODEX found everything from the logs.

To top this off the modified the woocommerce/templates/checkout/form-billing.php

If you have been hacked recently this incase its wide spread!

submitted by /u/ntr4nce
[link] [comments]
  •  
❌