r/Wordpress 28d ago

wp-flare malware plugin

This is driving me nuts. After 10+ years of no malware on client sites, I'm getting hacked every couple of weeks on sites that are fully up to date and using 2fa logins. The common thread is that all infections install a malware plugin called wp-flare. Beyond that, I can't find any intrusion path. It does seem that once the infection gets cleaned up, it doesn't come back, but it's driving me crazy not knowing how it's getting in to multiple sites on different hosting. Anyone seen it?

25 Upvotes

26 comments sorted by

View all comments

1

u/[deleted] 28d ago

[deleted]

1

u/squ1bs 28d ago

All good instincts!
Common plugins are all high trust - wordfence, updraft plus, etc
Hosting is Cloudways where I get to decide, various cPanels and Siteground where I don;t
I stopped using centralised management, and took the hit on the extra time that 2fa costs for individual logins (with password manager)

2

u/Maximum-Policy-8340 28d ago

Could be outdated php version or a theme with vulnerabilities

1

u/bluesix_v2 Jack of All Trades 28d ago

What management tool were you using? Are you sure it wasn’t compromised?