The Copywriter's Crucible

Ahhhhh!! My blog has been hacked!!!!! How to avoid this happening to you

wordpress hackedI’d always believed that, much like email scams and credit card fraud, having your website hacked is the sort of thing that happens to other people, but never to you. After all, I’d never be so foolish as to allow tricksters to get the better of me! Unfortunately, I fell foul of this fallacy last Friday.

Upon visiting my website I discovered nasty looking warning signs plastered all over the home page and in my WordPress’ admin screen. Thinking it was probably a plugin playing up, I logged into my WordPress theme’s support forum to get some answers.

Unfortunately, the issue wasn’t so innocent or simple to solve.

In super quick time, I got a response from my theme’s creator, Andon, with the words every website owner dreads – ‘Matt, I think your website has been hacked’. Not exactly the best news to receive last thing on a Friday.

Thankfully, Andon also gave me some salient advice on something every WordPress owner needs to know, and how to protect against it: In  July and early August there was a security vulnerability discovered with TimThumb script used in some WordPress themes and plugins.

So if you haven’t updated your theme in a while, you could be at risk, and should follow these steps to lockdown your WordPress website:

Thankfully, the hackers didn’t do much damage (as far as I can tell), and I was still able to login and rescue it from their clutches.

There’s still some ugly warning messages all over my admin panel and for some reason three portfolio posts were sent to subscribers yesterday(?). But other than that, I think I got away lightly.

Otherwise I might not be writing to you now.

Exit mobile version