Trying to find injection source

[ad_1]

A malware injection is happening every Monday morning that adds a script to the contact menu item of the primary header menu. Its easy to just remove it but whats the best way to track down what is causing this?

https://preview.redd.it/ekr2dqictznd1.png?width=1206&format=png&auto=webp&s=ee40f4fb04a460da797a985a1bcc996f2282a4e5

[ad_2]
2 Comments
  1. First things first:

    * check if every plugin and theme is updated
    * check if there is any plugin that isn’t supported for a longer period of time

    It can help you diagnose the root of the problem.

    Do you maybe have logs of when exactly changes are made? Are they at the identical time of the day?

    You can disable your plugins for a brief time when it’s happening.

    Another idea is to check if contact menu item is changed via WordPress admin panel (any logs of editing it?) or is it done directly on your database.

 

This site will teach you how to build a WordPress website for beginners. We will cover everything from installing WordPress to adding pages, posts, and images to your site. You will learn how to customize your site with themes and plugins, as well as how to market your site online.

Buy WordPress Transfer