Injected Code Breaking the Admin Area
Malicious code had been injected into script files across an entire WordPress installation, breaking the admin area and parts of the online store. The code was cleaned from every affected file, the site was updated by hand, and external monitoring was recommended because the entry point was not found.
The WordPress admin area and some areas of the website stopped functioning, and the browser console showed multiple errors.
Malicious code had been injected into the JavaScript files across the whole WordPress installation. The pattern suggested an automated bot scanning for vulnerable sites, not a person, and likely earlier attempts. The entry point could not be identified.
The injected code was cleaned from every affected script file. WordPress core and plugins were updated manually, because standard updates would not reliably replace files on this unusual server layout. An external malware-monitoring service was recommended in case a backdoor remained, along with a fresh backup and a second check after a day or two.
The site and admin area were working again after the cleanup, and a follow-up check was carried out.
Anonymised historical recovery completed by the team behind Dr Web. Scope and findings vary by website.
Get My Website Checked