Card-Skimming Script on a Checkout Page
A malicious script built to capture card details on a checkout page led the hosting provider to suspend the account, taking every site on it offline. The infected site was isolated, cleaned, stripped of abandoned plugins and brought fully up to date, and a second site on the account was updated and hardened.
The hosting provider suspended the account after a malware report. Three business websites went offline at once, including two that were not infected.
The compromised site carried malicious JavaScript designed to steal card details from its checkout page. Four abandoned plugins with known security problems were installed, one of them withdrawn from the official plugin directory. The site was an old build that had gone unmaintained.
The infected site was taken offline and an off-server backup kept while the account was reinstated. The site was then cleaned, every plugin with known security problems was removed, and WordPress core and the remaining plugins were updated. The second site on the account was updated and given extra hardening, and routine updates were taken over from then on.
WordPress core and all remaining plugins were confirmed up to date after the cleanup, and a malware scan was run and reported clean.
Anonymised historical recovery completed by the team behind Dr Web. Scope and findings vary by website.
Get My Website Checked