anonymously created Admin account on WP
-
Start by saying, I have not been diligent applying patches to my site – afraid something would break. Have perhaps a dozen plug-ins.
Starting in January 2024, I noticed a new Admin account logged in with a seemingly random set of alphabetic characters, reported via WordFence.
Contacted my host provider and they claimed it was nothing, but managed to remove the account. I later re-created it successfully and created a password for it, and find it STILL does not show up in a list of administrators.
I’m afraid someone has hacked my system and I don’t know where to turn to resolve this. Note, I have now applied ALL updates to the site.
Thanks in advance for any and all help!
Peter
WP.com: Yes
Jetpack: No
Correct account: YesThe blog I need help with is: (visible only to moderators and staff)
-
You say you contacted your hosting provider. Are you using a host other than WordPress.com?
These forums can only provide support to sites hosted directly by WordPress.com
-
We can’t help as your site isn’t running on the wordpress.com platform but is selfhosted. To get further help you must take a look in the documentation or ask for advice in the forums at https://wordpress.org/
Not applying patches or keeping your plugins and wordpress version not up to date, is like leaving the door of your house open for burglars.
-
No, it is not hosted by WordPress.org/Wordpress.com. :-/ They weren’t very helpful unfortunately.
-
I realize that not patching was risky…I also realize that sometimes patches to “fix” things sometimes break things… that the end-user is sometimes the alpha-tester and I didn’t want to be that either. I wasn’t equipped to handle backing out of the patch.
-
If your current hosting provider is not doing a good job supporting your site, I would suggest moving to a new host.
Every WordPress site needs a host. This guide explains WordPress.com hosting and covers the most common questions you may have about hosting a website. WordPress Hosting “WordPress” (or WordPress.org) is a free software that can be installed with a number of companies. WordPress.com is one, and there are hundreds of others. By purchasing a WordPress.com plan, you will have everything y -
For me, there is an intellectual curiosity on how an admin account doesn’t show up when listing Admin accounts through the WP interface – yet the Administrator count reflects it. The account does exist but hidden. Surely, there are back-end ways through SQL perhaps, that one can list all admin accounts side-stepping the GUI interface.
No one is curious about this? :-?
-
I agree it sounds concerning, but I don’t think it would apply to sites hosted here. We use the core version of WordPress software and users don’t typically have interaction with patches or updates. The technical side of blogging is, for the most part, handled by the platform.
- The topic ‘anonymously created Admin account on WP’ is closed to new replies.
