We have several WordPress sites that lately have been under attack. Despite numerous WordFence and other scans thehackers are still getting in. I traced the latest file they created by comparing the millisecond timestamp to a log entry that looked like:
[11/Dec/2024:18:07:48 -0500] “POST /?KQOB=DtWtG HTTP/1.1” 200
We don’t understand what this URL is doing, what script is being activated and how to block it. Can anyone advise me.
Thanks, J. K.
We’ve run WordFence scans and removed or cleaned tagged files. Checked plugins.
Jeffrey Koch is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
3