• Resolved franckw

    (@franckw)


    Hi

    Why my site get a lot of spam and hacker try to login on my website when active your plugin?

    This is the second time.

    The first time, when I installed your plugin, then get a lot of spam and hacker try to login on my website, every day around 50-100 spam and hacker try to connect to the admin page.

    When I have disabled your plugin, then the spam and hacker was stopped too.

    Yesterday, I have active your plugin to try again, but until now, I already get around 20 spam and hacker try to login to the admin page.

    This is very dangerous and bad, do you know what is the problem?

    Thank you

Viewing 5 replies - 1 through 5 (of 5 total)
  • Plugin Author lukeseager

    (@lukeseager)

    Hi,

    I’ve not had any reports of similar issues for other users. Can you confirm:

    The version number of WP Persistent Login you’re using.

    The version number of WordPress you’re using.

    If you’re using the Free or Premium version of WP Persistent Login.

    Thanks,
    Luke

    Thread Starter franckw

    (@franckw)

    Hi

    Version of WordPress is 6.0.2

    Your free plugin with last version.

    Since I have disabled your plugin yesterday, the spam/hacker stopped too.

    Please check if something wrong with your plugin.

    Thank you

    Plugin Author lukeseager

    (@lukeseager)

    Hi,

    Thank you for confirming. I don’t believe there is anything in my plugin that would cause this issue, the most likely problem is that one (or more) of the plugin files has been altered in some way, or that there is a vulnerability elsewhere on your website or server.

    Do you have a plugin like Wordfence installed on your website? If not, I would recommend installing that and running a full scan. It will check to see if plugin files have been changed compared to the files that are on the WP plugin directory.

    Alternatively, if you want to email me the persistent login plugin folder from your website, I can take a look at it myself to see if there are any differences.

    Either way, I would recommend installing Wordfence and running a full scan as that will help you ensure that whoever was trying to get into your website didn’t manage to leave something behind on your server.

    As I say, I’ve checked my plugin over, there is no malicious code in it, and I’ve had no reports of similar issues with any other user. I believe this is an isolated problem, either caused by plugin files being changed or downloaded from an unofficial source, or a vulnerability elsewhere on your website or server.

    Thanks,
    Luke

    Thread Starter franckw

    (@franckw)

    Hi

    I have tested again with the last 30 hours, this time, no one spam or hacker try to login to my site.

    Maybe last time was just a coincided. I will test with more time and let you know if something wrong.

    Thank you

    Plugin Author lukeseager

    (@lukeseager)

    Hi, glad to hear that there hasn’t been a problem since. Please do let me know if you have an issue in the future.

Viewing 5 replies - 1 through 5 (of 5 total)
  • The topic ‘Get a lot of spam/hacker login when active your plugin?’ is closed to new replies.