Yellow Cherry Placeholder

Warning for WordPress Users

An ongoing Malversting Campaign reported originally in July by Wordfence. This has been reported in the last week to have started to exhibit a more dangerous behavior than the common redirection to harmful/spam content, in the form of creating user accounts with administrative permissions.

The user that is being created has the following details: wpservices@yandex.com and the password w0rdpr3ss (although this may change). Once the user is in place on the website they are then free to install further backdoors and perform further malicious activity.

Now that it has become more serious we are urging all of our WordPress Customers who are not on a support package with us to ensure your website is up to date. We are strongly advising to install the Wordfence Security Plugin so you can be alerted to any problems that manifest on your site.

The known plugins currently under attack in this campaign are:

For more advice please contact the team on support@yellowcherry.uk