{"id":19034961,"date":"2026-10-02T14:00:00","date_gmt":"2026-10-02T14:00:00","guid":{"rendered":"https:\/\/wordpress.org\/support\/?post_type=topic&#038;p=19034961"},"modified":"2026-10-02T14:30:22","modified_gmt":"2026-10-02T14:30:22","slug":"webshells-uploaded-through-unknown-vulnerability","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/webshells-uploaded-through-unknown-vulnerability\/","title":{"rendered":"Webshells uploaded through unknown vulnerability"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Hello,<br \/><br \/>Since yesterday attackers have been uploading webshells to my \/tmp directory using POST requests to \/wp-admin\/admin-ajax.php. I have WP and all plugins fully patched and am trying to figure out how to block these uploads. My AV scanner is so far deleting the files which does stop the attacks.<br \/><br \/>What I am seeing in the logs is a 4 second burst of these POST requests from the same IP with a different user agent for every request.<br \/><br \/><code>POST \/wp-admin\/admin-ajax.php HTTP\/1.0\" 403<\/code><br \/><br \/>Then right away my AV software reports it deleted a file like this about 60 times<br \/><br \/><code>\/tmp\/php6cs0t9 Generic.PHP.WebShell.X.A18DB3F0<\/code><br \/><br \/>What is strange is that the requests does return a 403, there are no other POST request at the time of the AV reports. I do run Wordfence, possibly this blocks the request after the upload takes place. Does anyone have a ideas on how to deal with this?<\/p>\n","protected":false},"template":"","class_list":["post-19034961","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19034961","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":1,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19034961\/revisions"}],"predecessor-version":[{"id":19034986,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19034961\/revisions\/19034986"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=19034961"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}