• Is WordPress hacked? I checked my email this morning and so lots of comment spam mailed to me from my WordPress site.
    What alarmed me is that they included private posts and draft articles.
    Is this a new undiscovered problem in WordPress security?
    Most of the spam links to these websites
    http://www.we_are_stupid_spammers.com
    [URL moderated]

Viewing 4 replies - 1 through 4 (of 4 total)
  • Thread Starter mydeja

    (@mydeja)

    Something else I noticed:
    All the private posts had just one comment, where as the public ones had multiple posts.
    Is is as though whatever script is in use is able to detect that and just post as single comment on private posts just for the email.

    Thread Starter mydeja

    (@mydeja)

    You haven’t answered my question.
    I need to know whether other WordPress users have experienced the same thing.

    It’s because they are using a script to spam you.
    The script picks a post#ID, and spams it, increases the post#ID and spams that… repeat ad nauseum.
    It’s a script, not a person.
    Go here:
    http://www.tamba2.org.uk/wordpress/spam
    Install TG’s code – this will stop it happening again, then follow the guide at the bottom to remove the junk from the database.
    Also install more spam protection.
    They aren’t hacking you.

    Thread Starter mydeja

    (@mydeja)

    Sorry if I sounded abrupt
    I did not expect the scripts to be able to spam private or draft posts as links to them do not show up.
    It gives the impression that private and drafts posts are visible to the spammers.
    I just need to be sure. It would help if if the comment code checked that the user was authorised to add comments to drafts or private posts.

Viewing 4 replies - 1 through 4 (of 4 total)
  • The topic ‘Is WordPress hackable by spammers?’ is closed to new replies.