Author Topic: Potential Infection for WordPress Blogs  (Read 1710 times)

Bill Hiatt

  • Series unlocked
  • ******
  • Posts: 5238
  • Thanked: 1951 times
  • Gender: Male
  • Tickling the imagination one book at a time
    • Bill Hiatt's Author Website
Potential Infection for WordPress Blogs
« on: November 07, 2019, 02:10:46 AM »
Since many of us use WordPress for our websites, I thought it would be good to mention WP-VCD, which has been around for a while but is now the single most common WordPress infection, according to Wordfence.

WP-VCD is so widespread because site admins install it themselves. It's spread through sites advertising free theme and plugin downloads. (Of course, a lot of themes and plugins are free but should typically be downloaded through the built-in mechanism in WordPress (plugins), from a known repository, such as one your hosting company may provide, or directly from the creator's website. However, the lure isn't the offer of free downloads for already-free products. It's free downloads of premium products. I don't imagine most of us are in the habit of stealing other people's hard work, but if you see a site with lots of free themes and plugins advertised, don't use it. If you want to doublecheck, search for the some of the themes or plugins advertised to see if they are actually premium items. Then you know for sure that you need to stay away.

Because an admin has installed the infected product, it bypasses some security precautions. WP-VCD isn't dangerous unless you do that--except in shared hosting environments. It can spread from one hosted site to another in such a situation, so it would be good to check with your host to see if any precautions are in place. (The free sites on WordPress.com aren't affected because users can't install themes and plugins.)

For more information, see https://www.wordfence.com/blog/2019/11/wp-vcd-the-malware-you-install-on-your-own-sites/
« Last Edit: November 07, 2019, 02:13:31 AM by Bill Hiatt »


Tickling the imagination one book at a time
Bill Hiatt | fiction website | Facebook author page |
 
The following users thanked this post: Joe Vasicek, Wonder, Kristen.s.walker