Hi @murielzs, thanks for reaching out!
If your host has no issue with sites on their platform running Wordfence and didn’t force the deactivation themselves, it does seem suspicious as the plugin doesn’t deactivate itself by design for any reason. Check with your host’s support if you’re not sure though.
We always recommend that you make a full backup of the site before making any further changes. After this, make sure to remove any users with administrative access that you don’t recognize as a priority. That’s just in case somebody has created a new account to retain access to your site. It’s possible that an attack vector outside of WordPress has been used, though.
As a rule, any time I think someone’s site has been compromised I also tell them to update their passwords for their hosting control panel, FTP, WordPress admin users, and database. Make sure to do this.
I will provide our site cleaning instructions for you, just in case the steps can help: https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/
XML-RPC requests are one of the most common brute force/credential stuffing attack methods so we always recommend using long unique passwords along with 2FA for your administrative accounts.
Additionally you might find the WordPress Malware Removal section in our free Learning Center helpful.
Many thanks,
Peter.
Hi Peter,
Thank you for your advice. I have checked with my server and they haven’t touched the plugin.
I have had at least 6 occurrences. The wordfence notifications indicate someone with a username “”, showing different Ip addresses and locations every time. But nothing else has been happening on my website…. so I am not sure if I have been hacked.
I have deleted all the users on my website and changed my password.
And thank you for sharing the info about the malware removal section, I will have a look.