WPIntell

Source evidence

[Plugin: myPortfolio Plus] Malware detected at install

myPortfolio Plus · support · 2011-07-22T16:32:00+00:00

complaintsentiment
highseverity
0.97relevance
1replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

5 / 34 rows with source links

14.7% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

29 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
apogeeza unresolved
Malware Warning: This plugin may have been compromised (I’m referring to the recent mass-password reset bit.) I installed myPortfolio plus on my site via wp-admin/plugin-install.php, but I got interrupted and didn’t get round to creating any content with it, so the plugin remained in an “install only” state. The next day a security email arrived with the notice quoted below. It seems the plugin automatically created “JspWebshell 1.2.php” and “Copie de c99.php” in the wp-content folder root and the 2 malware files was detected by Websitedefender. This was also confirmed through a few Google searches that I ran on the file names. I urge the author to check and confirm the zip on WordPress.org is verified malware clean. WebsiteDefender discovered the following security problem/s: Critical severity alerts: Malicious file found (JspWebshell 1.2.php – B.C.T JSP web shell v1.2) Possible malicious file found (Copie de c99.php – Suspicious PHP Code) Medium severity alerts: New WordPress plugin installed (myPortfolio Plus) WordPress plugin deleted (xxx) WordPress plugin deleted (xxx) WordPress plugin requires update (xxx) Low severity alerts: File structure change: 24 files modified File structure change: 45 new files found Informational alerts: File structure change: 6 files deleted http://wordpress.org/extend/plugins/my-portfolio-plus/ Please contact the plugin’s developer directly. If you do not a response within a few days, please contact plugins@wordpress.org

Comments

1 shown
esmi 2011-07-22T16:34:00+00:00

Please contact the plugin’s developer directly. If you do not a response within a few days, please contact plugins@wordpress.org