On the morning of July 20, we discovered that several of our hosted Connect IN sites had been affected by a recently disclosed security vulnerability in WordPress.
This vulnerability allowed outside attackers to gain administrative access without first knowing a valid username or password. They used that access to create unauthorized administrator accounts and install fake plugins. These plugins could allow someone to run commands on the web server and make additional changes to the affected sites.
After identifying the affected WordPress sites, we took the following steps:
- Identified the IP addresses associated with the malicious plugins in the server’s access logs and banned them from accessing the server.
- Removed the fake plugins from the active plugin folders.
- Deleted the unauthorized administrator accounts created by the attackers.
- Invalidated existing WordPress login sessions.
- Force-updated all hosted WordPress sites to version 7.0.2, which contains the security fix.
- Verified the WordPress core files and reviewed the sites for additional signs of unauthorized changes.
This incident is an important reminder that website security issues can affect more than the appearance of a site. A vulnerability may allow someone to create accounts, install files, or make changes behind the scenes without immediately disrupting the public website. Promptly installing security updates and monitoring for unusual activity help reduce that risk.
Because all hosted Connect IN sites were updated as part of this response, some sites may experience unexpected issues with older themes or plugins. If you notice anything that is not working correctly on your WordPress site, please submit a Helpdesk ticket and we’d be happy to investigate further.
Connect IN Technical Support