Moderator
Jan Dembowski
(@jdembowski)
Forum Moderator and Brute Squad
That’s very serious. Aside from your site being hacked do you have any evidence or can you point to code that makes this plugin responsible for that?
I guess I’m asking how you managed to determine that it was this plugin that caused your site to be compromised?
Edit: Also it looks like you’ve been hacked before.
http://wordpress.org/support/topic/hacked-47?replies=2
If you had not properly deloused your installation then the hack will always come back eventually.
The hack put code at the top of the header and added a whole page of content to the home page. After looking through the theme files to make sure it wasn’t in there, I deactivated plugins one by one and reactivated them. This was the plugin that caused the problem. I am not sure if it was merely a vulnerability in the plugin or a bad plugin. This incident was on an unrelated site on a different server. I checked the usual suspects like uploads and .htaccess and all were normal. No files on the server had been recently modified that would have caused an issue.
I can assure you, this plugin has not been maintained for a LONG time. If there is a vulnerability that caused your issue, I most definitely apologize, but there was no malicious intention on my part.