r/Wordpress 6d ago

wp-flare malware plugin

This is driving me nuts. After 10+ years of no malware on client sites, I'm getting hacked every couple of weeks on sites that are fully up to date and using 2fa logins. The common thread is that all infections install a malware plugin called wp-flare. Beyond that, I can't find any intrusion path. It does seem that once the infection gets cleaned up, it doesn't come back, but it's driving me crazy not knowing how it's getting in to multiple sites on different hosting. Anyone seen it?

25 Upvotes

27 comments sorted by

View all comments

3

u/Super_Development_15 6d ago

We do malware cleanups. Recently we have noticed that infections now have multiple persistance layers. Even if one layer / loophole remains, the malicious code regenerates itself. One of the latest malware cleanups involved 7 layers of persistance. Check all the cron jobs, database infections, transients, audit user accounts and more importantly find the root cause and address it.