WordPress.org

Ready to get started?Download WordPress

Forums

Disabling WP Supercache Caused Major Concern Today (7 posts)

  1. seahawknationblog
    Member
    Posted 3 years ago #

    Okay i disabled WP Supercache today and got an error message above my admin bar saying there was an error in my wp-admin/admin.php & blogheader.php

    I went ahead and deleted thinking it was something to do with WP Supercache, when i deleted it i got the white screen of death, tried deleting advanced-cache.php & wp-cache-config.php.

    After i did this nothing changed, i went to the front page of my blog and couldnt belive what i was seeing, it was my wp-config.php on my front page of my blog, i couldnt belive this, anyone could have got my username, password, and anything else they wanted, does anyone know what the hell this is, and have they heard oif this, been using wordpress for over 3 years and i have never heard anything like this before?

    I got it fixed with a backup at the databse level and it fixed this issue but im afraid it might happen again?

  2. After i did this nothing changed, i went to the front page of my blog and couldnt belive what i was seeing, it was my wp-config.php on my front page of my blog

    Change your passwords ASAFP if you haven't already.

    I've never heard of that happening either though. I'm not sure how it could, since the config file isn't a ... render-able PHP file. At least not by your browser.

  3. Exactly, I have no idea how it happened either, since server show index.html or index.php first, or just a dir if neither are present...

  4. And if you go to http://domain.com/wp-config.php you just get a blank screen anyway.

  5. Ron Rennick
    MultiSite Guru
    Posted 3 years ago #

    See http://wordpress.org/support/topic/security-risk-when-uninstalling-wp-super-cache

    If you had quick cache installed first, that's your culprit.

  6. seahawknationblog
    Member
    Posted 3 years ago #

    I did have quick cache installed first, i deleted it the day before and un-installed it.
    Wow i call that a very serious security issue they need to fix!!!

    Ipstenu: I changed everything including password immediately.

  7. seahawknationblog
    Member
    Posted 3 years ago #

    I would say anyone who uninstalls Quick Cache be aware to move the line define wp_cache true down a notch

    <?php define('WP_CACHE', true); Should look like this>>

    #############################
    <?php

    define('WP_CACHE', true);

Topic Closed

This topic has been closed to new replies.

About this Topic