{"id":18974839,"date":"2026-07-25T14:45:18","date_gmt":"2026-07-25T14:45:18","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/wpsvc-hack\/"},"modified":"2026-07-25T14:45:18","modified_gmt":"2026-07-25T14:45:18","slug":"wpsvc-hack","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/wpsvc-hack\/","title":{"rendered":"wpsvc Hack"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Hi there,<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Somehow user wpsvc_5b46a52b4dcc found a way in and performed some corruptive actions on the site. Logging in, uploading and activating a plugin. It&#8217;s fair to say some of the existing plugins were not updated to latest. Not sure as to the explanation of leakage of credentials.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The site is 90% functional at least, some (BuddyPress) user data is compromised, and error log is available for perusal.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Since a backup of the site was performed last month, we plan to change passwords before restoring, if you are interested in viewing the payload, please do it prior to the rollback.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thanks.<\/p>\n","protected":false},"template":"","class_list":["post-18974839","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/18974839","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/18974839\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=18974839"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}