Make WordPress Core

Opened 7 years ago

Closed 7 years ago

#47462 closed defect (bug) (invalid)

Someone keeps gaining access to my site as an admin

Reported by: madecker12 Owned by:
Priority: normal Milestone:
Component: Security Version: 5.2.1
Severity: normal Keywords:
Cc: Focuses:

Description

I have a potential hacker (dreamsbadtoyou2@…) that has somehow added themselves as an admin to my website. I do not have the box checked under general settings that even allows someone to request permission, but they were still able to set themselves up as an admin. I took them off, checked the box and set the default role to blocked, but they tried again and were successful in making themselves an admin. This is a HUGE problem that I haven't encountered before and it needs to be addressed immediately.

Change History (1)

#1 @SergeyBiryukov
7 years ago

  • Milestone Awaiting Review
  • Resolutioninvalid
  • Severity criticalnormal
  • Status newclosed

Hello @madecker12, welcome to WordPress Trac!

I'm sorry that your site seems to be hacked. Unfortunately we can't help you with your hacked site here. Please follow the steps mentioned on https://codex.wordpress.org/FAQ_My_site_was_hacked or try our support forums at https://wordpress.org/support/forums/.

In case you have found a a security vulnerability in WordPress please read https://make.wordpress.org/core/handbook/testing/reporting-security-vulnerabilities/.

Note: See TracTickets for help on using tickets.