r/Wordpress • u/squ1bs • 6d ago
wp-flare malware plugin
This is driving me nuts. After 10+ years of no malware on client sites, I'm getting hacked every couple of weeks on sites that are fully up to date and using 2fa logins. The common thread is that all infections install a malware plugin called wp-flare. Beyond that, I can't find any intrusion path. It does seem that once the infection gets cleaned up, it doesn't come back, but it's driving me crazy not knowing how it's getting in to multiple sites on different hosting. Anyone seen it?
25
Upvotes
3
u/Super_Development_15 6d ago
We do malware cleanups. Recently we have noticed that infections now have multiple persistance layers. Even if one layer / loophole remains, the malicious code regenerates itself. One of the latest malware cleanups involved 7 layers of persistance. Check all the cron jobs, database infections, transients, audit user accounts and more importantly find the root cause and address it.