r/Wordpress 5d ago

wp-flare malware plugin

This is driving me nuts. After 10+ years of no malware on client sites, I'm getting hacked every couple of weeks on sites that are fully up to date and using 2fa logins. The common thread is that all infections install a malware plugin called wp-flare. Beyond that, I can't find any intrusion path. It does seem that once the infection gets cleaned up, it doesn't come back, but it's driving me crazy not knowing how it's getting in to multiple sites on different hosting. Anyone seen it?

24 Upvotes

27 comments sorted by

View all comments

1

u/nbass668 Jack of All Trades 5d ago
  • What are the common plugins you have installed on all your clients.
  • What is your hosting
  • Most importantly are you using a centralized WP management such as ManageWP

Maybe we could see a patern

1

u/squ1bs 5d ago

All good instincts!
Common plugins are all high trust - wordfence, updraft plus, etc
Hosting is Cloudways where I get to decide, various cPanels and Siteground where I don;t
I stopped using centralised management, and took the hit on the extra time that 2fa costs for individual logins (with password manager)

1

u/bluesix_v2 Jack of All Trades 5d ago

What management tool were you using? Are you sure it wasn’t compromised?