WordPress Security

by 5 replies
7
Hi guys,

I've posted this in the website Design forum as well, so sorry for any double-up.

Just need some advice, I've started blogging for a new client & over the last few days have had some new users appear on the site. They used an email address whose url led to a dodgy-looking Russian site. I'm pretty sure it's a spam bot that's gotten in and set them up as the site hadn't been updated to the latest version of WP. I've updated it & deleted the spam users, but am wondering what is the best way to secure the site (apart from changing passwords)? I'm pretty sure WP was setup on this site with an auto install, is there any way to correct this with the current setup, or do I need to uninstall WP & do a manual WP install?
I'm not the most technically advanced Warrior, so any and all help would be invaluable.

Cheers,
Sissy
#programming #security #wordpress
  • What role was assigned to the new 'spam users'? If they were added as Subscriber, and you had the blog set to allow new registrations, it should be enough to just delete them and then disallow new user registrations.

    If these users had any other role than Subscriber, it's a pretty much sure sign that the WP install has been hacked or compromised. If so, deleting the WP files isn't enough. The safest thing to do is to start over from scratch with a clean install and fresh database. That may not be an option if there are a lot of existing posts or the site has been indexed in the SEs for any length of time.

    If that's the case, you may have to bite the bullet and and hire a bug cleaner to disinfect your wp-content folder and the database. Not cheap, but probably unavoidable if you can't do it yourself and you can't start fresh.
    • [ 1 ] Thanks
  • I used to get tens/hundreds spam comments a day on our blogs (probably from bots) until I installed the re-Captcha Wordpress plugin. This stopped them overnight except for the occasional one easily managed.

    Neil
    • [ 1 ] Thanks
  • Banned
    [DELETED]
  • there are some steps here that should be followed
    Hardening WordPress « WordPress Codex
    • [ 1 ] Thanks
  • Banned
    [DELETED]
    • [1] reply
    • Thanks so much guys for all of your advice. The WP install was an auto one using Fantastico, and there's a lot of content on the site, so deleting the database isnot preferable, so looks like I'll be researching bug cleaners - any suggestions on a good one?

      Thanks again,
      Sissy
      • [1] reply

Next Topics on Trending Feed