Make WordPress Core

Opened 5 years ago

Closed 5 years ago

Last modified 5 weeks ago

#53270 closed defect (bug) (invalid)

My company website is hacked by the Japanese keyword hack. How to delete XML sitemap full of spam hacks?

Reported by: ganapathy11's profile ganapathy11 Owned by:
Milestone: Priority: normal
Severity: critical Version: 5.7.2
Component: Security Keywords:
Focuses: Cc:

Description

My company website is hacked by the Japanese keyword hack. We have cleaned almost everything (By deleting our .htaccess file from our site and uploaded default version of the .htaccess file). Now our XML sitemap has many spam links listed. We cannot find a way to delete/clear it. We tried turning off Sitemaps and then back on. We have reinstalled Yoast. Here is the XML sitemap link - https://scgroup.global/sitemap.xml

Any advice please?
Please see the screenshots.
https://storage.googleapis.com/support-forums-api/attachment/thread-110960078-12212445501605327770.PNG
https://storage.googleapis.com/support-forums-api/attachment/thread-110960078-12212445501605329471.PNG

Attachments (2)

Site - Hack1.PNG (232.8 KB) - added by ganapathy11 5 years ago.
URL Inspection in Google Search Console
XML sitemap.PNG (74.5 KB) - added by ganapathy11 5 years ago.
XML sitemap full of spam hacks

Download all attachments as: .zip

Change History (5)

@ganapathy11
5 years ago

URL Inspection in Google Search Console

@ganapathy11
5 years ago

XML sitemap full of spam hacks

#1 follow-up: @Presskopp
5 years ago

  • Resolution set to invalid
  • Status changed from new to closed

First please read https://wordpress.org/support/article/faq-my-site-was-hacked/

Please do not use Core Trac for WordPress troubleshooting, open a topic on support forum instead: https://wordpress.org/support/forum/how-to-and-troubleshooting/#new-topic-0

This trac is for reporting bugs in WordPress core. Your issue is not a bug in the core.

#2 in reply to: ↑ 1 @ganapathy11
5 years ago

Replying to Presskopp:

First please read https://wordpress.org/support/article/faq-my-site-was-hacked/

Please do not use Core Trac for WordPress troubleshooting, open a topic on support forum instead: https://wordpress.org/support/forum/how-to-and-troubleshooting/#new-topic-0

This trac is for reporting bugs in WordPress core. Your issue is not a bug in the core.

Okay. Will definitely do that in future. Thanks!
Just to let you know that our developer restored the website with backups.
I guess, the issue is due to "Wordpress version 5.7.1". Our developer team is missed to update security release "WordPress 5.7.2" on timely manner.

#3 @SergeyBiryukov
5 years ago

  • Keywords Japanese keyword hack spam Wordpress link injection XML sitemap removed
  • Milestone Awaiting Review deleted

Thanks for the follow-up!

Adjusting the keywords per Trac Workflow Keywords.

Note: See TracTickets for help on using tickets.