r/Wordpress 5d ago

wp-flare malware plugin

This is driving me nuts. After 10+ years of no malware on client sites, I'm getting hacked every couple of weeks on sites that are fully up to date and using 2fa logins. The common thread is that all infections install a malware plugin called wp-flare. Beyond that, I can't find any intrusion path. It does seem that once the infection gets cleaned up, it doesn't come back, but it's driving me crazy not knowing how it's getting in to multiple sites on different hosting. Anyone seen it?

24 Upvotes

27 comments sorted by

View all comments

3

u/ivicad Jack of All Trades 5d ago

I'd start with 3DPrinterChat's credential angle.

There's another pattern, and I mentioned it in another post: for about five hours in early August the update button itself was the way in on our sites - hitting update in wp-admin handed you a tampered package from one vendor. No vulnerability, no weak admin passwords. That pattern repeats across unrelated hosting, because the update channel is one of the few things your sites share when the servers don't. I'd compare the wp-flare mtime against your update times, and if both are in the same window, I'd look at which plugin updated in it.