Conversation
supportMalware Warning: This plugin may have been compromised (I’m referring to the recent mass-password reset bit.) I installed myPortfolio plus on my site via wp-admin/plugin-install.php, but I got interrupted and didn’t get round to creating any content with it, so the plugin remained in an “install only” state. The next day a security email arrived with the notice quoted below. It seems the plugin automatically created “JspWebshell 1.2.php” and “Copie de c99.php” in the wp-content folder root and the 2 malware files was detected by Websitedefender. This was also confirmed through a few Google searches that I ran on the file names. I urge the author to check and confirm the zip on WordPress.org is verified malware clean. WebsiteDefender discovered the following security problem/s: Critical severity alerts: Malicious file found (JspWebshell 1.2.php – B.C.T JSP web shell v1.2) Possible malicious file found (Copie de c99.php – Suspicious PHP Code) Medium severity alerts: New WordPress plugin installed (myPortfolio Plus) WordPress plugin deleted (xxx) WordPress plugin deleted (xxx) WordPress plugin requires update (xxx) Low severity alerts: File structure change: 24 files modified File structure change: 45 new files found Informational alerts: File structure change: 6 files deleted http://wordpress.org/extend/plugins/my-portfolio-plus/
Please contact the plugin’s developer directly. If you do not a response within a few days, please contact plugins@wordpress.org
Please contact the plugin’s developer directly. If you do not a response within a few days, please contact plugins@wordpress.org