Someone signed on who wasn’t me
-
Someone used my correct email to sign in to my WordPress account, with administrator access, who wasn’t me. They published a post that I had in draft form, but I don’t see what else might have been done. What do I need to do now to protect myself from someone who has access to my site?
The blog I need help with is: (visible only to logged in users)
-
Hi there,
Your site is not hosted with us on WordPress.com, and no one has logged into this WordPress.com account for more than a year until you reset the password yesterday.
To prevent something like this, make sure you have a strong, unique password, keep your WordPress version, theme and plugins up to date, consider using a 2FA plugin on your site, and also enable it for your email account, as someone who gains access to your email can reset your password on any other site or service that uses that email address. You can find more steps to improve the security of your self-hosted WordPress site here:
https://wordpress.org/support/article/hardening-wordpress/
For more help with this, please ask in the WordPress.org forums, as they provide support for the version of WordPress you’re using.
- The topic ‘Someone signed on who wasn’t me’ is closed to new replies.