Title: Webshells uploaded through unknown vulnerability
Last modified: October 2, 2026

---

# Webshells uploaded through unknown vulnerability

 *  [mvvvmd](https://wordpress.org/support/users/mvvvmd/)
 * (@mvvvmd)
 * [1 day, 8 hours ago](https://wordpress.org/support/topic/webshells-uploaded-through-unknown-vulnerability/)
 * Hello,
   Since yesterday attackers have been uploading webshells to my /tmp directory
   using POST requests to /wp-admin/admin-ajax.php. I have WP and all plugins fully
   patched and am trying to figure out how to block these uploads. My AV scanner
   is so far deleting the files which does stop the attacks.What I am seeing in 
   the logs is a 4 second burst of these POST requests from the same IP with a different
   user agent for every request.`POST /wp-admin/admin-ajax.php HTTP/1.0" 403`Then
   right away my AV software reports it deleted a file like this about 60 times`/
   tmp/php6cs0t9 Generic.PHP.WebShell.X.A18DB3F0`What is strange is that the requests
   does return a 403, there are no other POST request at the time of the AV reports.
   I do run Wordfence, possibly this blocks the request after the upload takes place.
   Does anyone have a ideas on how to deal with this?

Viewing 3 replies - 1 through 3 (of 3 total)

 *  Moderator [threadi](https://wordpress.org/support/users/threadi/)
 * (@threadi)
 * [1 day, 7 hours ago](https://wordpress.org/support/topic/webshells-uploaded-through-unknown-vulnerability/#post-19034996)
 * You mentioned WordPress and the plugins – what about your theme?
 * Also, check if you have any “must-use” plugins. If any look unfamiliar, delete
   them.
 * Examine the `wp-config.php` file to see if it contains anything that looks suspicious.
 * Check the entire `uploads` directory to see if there are any PHP files inside.
   Some plugins write files there, but if you don’t recognize them, delete them.
 * Also, go ahead and delete all language files in `wp-content/languages/`. Hackers
   often hide code inside their PHP files. Once deleted, WordPress will download
   fresh copies.
 * If you have a `wp-content/cache` directory, delete that as well; the plugins 
   that need it will recreate it.
 * In general, keep an eye out for any files that don’t seem to belong to anything.
 * Delete the `wp-admin` and `wp-includes` directories and re-upload their contents
   from a fresh download (matching your specific WordPress version) obtained from
   [https://wordpress.org/download/releases/](https://wordpress.org/download/releases/).
 * If you’d rather avoid that effort, check if you have a clean backup and restore
   it.
 * Afterward, you should take a look at this resource: [https://developer.wordpress.org/advanced-administration/security/hardening/](https://developer.wordpress.org/advanced-administration/security/hardening/)
 *  Thread Starter [mvvvmd](https://wordpress.org/support/users/mvvvmd/)
 * (@mvvvmd)
 * [1 day, 7 hours ago](https://wordpress.org/support/topic/webshells-uploaded-through-unknown-vulnerability/#post-19035023)
 * I have not seen any indication of the attack being successful, my AV software
   is stopping the attempts. I also have done various checks to see if anything 
   is out of order, this is not the case.
   I would like to know if there is a way
   to block these uploads to /tmp. Idealy I would like to figure out what they are
   exactly doing to get the files written /tmp.
 *  Moderator [threadi](https://wordpress.org/support/users/threadi/)
 * (@threadi)
 * [1 day, 5 hours ago](https://wordpress.org/support/topic/webshells-uploaded-through-unknown-vulnerability/#post-19035119)
 * If you want to know how to stop this, you need to figure out the path the request
   takes. You can send all sorts of things to the AJAX endpoint, but only a function
   that exists in your project could cause data to be stored in the /tmp directory.
   That function, in turn, could come from any part of your project. You need to
   find it. My list above can be a helpful tool for that. WordPress itself doesn’t
   do this.

Viewing 3 replies - 1 through 3 (of 3 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fwebshells-uploaded-through-unknown-vulnerability%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * In: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
 * 3 replies
 * 2 participants
 * Last reply from: [threadi](https://wordpress.org/support/users/threadi/)
 * Last activity: [1 day, 5 hours ago](https://wordpress.org/support/topic/webshells-uploaded-through-unknown-vulnerability/#post-19035119)
 * Status: not resolved

## Topics

### Topics with no replies

### Non-support topics

### Resolved topics

### Unresolved topics

### All topics
