[Plugin: myPortfolio Plus] Malware detected at install
-
Malware Warning:
This plugin may have been compromised (I’m referring to the recent mass-password reset bit.)I installed myPortfolio plus on my site via wp-admin/plugin-install.php, but I got interrupted and didn’t get round to creating any content with it, so the plugin remained in an “install only” state. The next day a security email arrived with the notice quoted below.
It seems the plugin automatically created “JspWebshell 1.2.php” and “Copie de c99.php” in the wp-content folder root and the 2 malware files was detected by Websitedefender. This was also confirmed through a few Google searches that I ran on the file names.
I urge the author to check and confirm the zip on WordPress.org is verified malware clean.
WebsiteDefender discovered the following security problem/s:
Critical severity alerts:
Malicious file found (JspWebshell 1.2.php – B.C.T JSP web shell v1.2)
Possible malicious file found (Copie de c99.php – Suspicious PHP Code)
Medium severity alerts:
New WordPress plugin installed (myPortfolio Plus)
WordPress plugin deleted (xxx)
WordPress plugin deleted (xxx)
WordPress plugin requires update (xxx)
Low severity alerts:
File structure change: 24 files modified
File structure change: 45 new files found
Informational alerts:
File structure change: 6 files deleted
The topic ‘[Plugin: myPortfolio Plus] Malware detected at install’ is closed to new replies.