• Resolved sleeplessindc

    (@sleeplessindc)


    Yesterday, I ran a Wordfence scan of my website and it said I had what looks like malicious code in my wp-admin/error_log. Wordfence helped me identify that the code belongs to error messages originating from the stop-spammer-registrations-plugin.

    Can you tell me why the following code is in my error log?

    [28-Apr-2016 17:41:28 UTC] WordPress database error You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '')' at line 3 for query select option_id,option_value,option_name
    from t68a5447_options where
    INSTR(LCASE(option_value), 'eval(') +INSTR(LCASE(option_value), 'eval (') +INSTR(LCASE(option_value), 'networkads') +INSTR(LCASE(option_value), 'document.write(unescape(') +INSTR(LCASE(option_value), 'try{window.onload') +INSTR(LCASE(option_value), 'escape(document[') +INSTR(LCASE(option_value), 'escape(navigator[') +INSTR(LCASE(option_value), 'document.write(string.fromcharcode') +INSTR(LCASE(option_value), '(base64_decode') +INSTR(LCASE(option_value), '(gzinflate') +INSTR(LCASE(option_value), 'UA-27917097-1') +INSTR(LCASE(option_value), 'w.wpquery.o') +INSTR(LCASE(option_value), '<scr'+')  made by do_action('stop-spammers_page_ss_threat_scan'), call_user_func_array, kpg_ss_threat_scan, include_setting, require_once('/plugins/stop-spammer-registrations-plugin/settings/kpg_ss_threat_scan.php')

    https://wordpress.org/plugins/stop-spammer-registrations-plugin/

Viewing 1 replies (of 1 total)
  • WordFence is finding the threat checking code in Stop Spammers. Stop Spammers might find the same code in WordFence.

    Either ignore the messages, or if they make you nervous, uninstall stop spammers.

    The code is in strings and is not executable. It is there so that Stop Spammers can check files for malicious code.

    Keith

Viewing 1 replies (of 1 total)
  • The topic ‘wp-admin/error_log collecting errors generated by Stop Spammers Spam Prevention’ is closed to new replies.