WordPress scam alert
Beware if you get an email claiming to be from the WordPress team warning of a vulnerability on your website and prompting you to download a "Patch" plugin and install it. The phishing email looks like this:
The Download Plugin link redirects victims to a fake landing page.
Once installed the plugin, which is installed in a directory called wpress-security-wordpress, adds a malicious administrator user and makes sure that this username is hidden.
It also creates a ‘backdoor’ which allows attackers multiple forms of access, granting them full control over your WordPress site.
Be on the lookout for this phishing email and do not click any links, including the Unsubscribe link, and do not install the plugin on your site.
I hope that helps.
Do you need some help? Get in touch on 0777 169 1194 for a free no-obligation chat.
Jane
Hi Jane, we received two of these emails and very nearly downloaded them, thanks for posting this on linked in. Regards Mike