Ok, this is where I curl up into the fetal position and start to cry. Tonight, over 30 of my posts have "hidden" injection spam for every pill on the planet, and I have done the following:
1. Printed off a list of all my users, and compared them to WP - nothing stood out, everyone matched up, no outsiders.
2. The log file plugin gave me some errors, so that didn't work - although it's mainly because I am probably doing something majorly wrong.
3. Most of my spam comes from particular (seemingly static) IP addresses.... namely this one:
OrgName: NetNation Communications Inc
OrgID: NNC
Address: Bentall Tower 5, Suite 200
Address: 550 Burrard Street
City: Vancouver
StateProv: BC
PostalCode: V6C-2B5
Country: CA
64.40.96.0 - 64.40.127.255
I have combed my template, and upgraded to 2.5.1, prayed to every God on the planet, sprinkled salt, holy water, and it's like some magic Gremlin is getting in....
The ads are changing, mainly just lines of text with pill names that are links - BUT - they are hidden, you can't see them in the post, it's in the HTML, and in the post when I view it from the Admin side.
So, I see in Audit Trail that the post has been modified (or in my case 30 posts have been modified) - I click the link, I see my post, and down below is a bunch of hyperlinks that would make any pill popper happy.
So then I go to the HTML viewer, delete the code, resave and it's gone - until they re-inject it.
The hyperlinks are NOT visible on my blog to the public, which is weird to me. I think they have hacked in to shove keywords into my blog, that would - if I had enabled - "sway" my google ads or something - I mean, I have no idea why?
Ok, so I am at a loss. I have no idea what is going on, but I would like to remedy this - and I need help.
Anyone have a miracle?