Possibly hacked? Possibly urgent?
-
Hi,
My boss just showed me something awfully strange on our company website, as pornographic links were being added during the wp_head action.
… what makes this strange is that we are NOT a porn company!
I was able to discover the issue was a plugin called WP Live Stats, made by a Sam Cunningham. The plugin isn’t in the WP Plugin Repo (and thus, I’m not sure why it was added to our site, I didn’t build it though), and visiting the plugin site (http://www.wpstatslive.info/wp-sats-live/, though I would guess they want wp-stats-live) gives me a 404. The base domain for the site gives me a brand new, fresh WordPress install.
What’s concerning, is that I was able to track the issue to a cURL call in his plugin that is hitting this link: http://www.wpstats.org/jquery-1.6.3.min.js, and is echo’ing the data on the page (this makes little to no sense to me).
When I remove the cURL call, the pornographic links are not added to the header, so I’ve just completely removed the plugin from the site, but when I go to that jquery link, I get a blank page, and wpstats.org takes me to wordpress.org, which worries me.
I guess to make this long story short, I don’t know if it was this plugin that was hacked, or if it’s possible the WordPress family of sites has been hacked, but I wanted to make sure everyone out there using this plugin should NOT have it activated (unless, of course, they want the porn links) and wanted to see if anyone with any pull in the WP community knew anything more about it.
Thanks a lot,
–d
The topic ‘Possibly hacked? Possibly urgent?’ is closed to new replies.