INCIDENT REPORT / IR-2024-1192 / CONFIDENTIAL
Platform: WordPress 6.4.3 / PHP 8.1 / MySQL 8.0
Critical — Severity 1
WordPress Installation Compromised
Current Status
Containment
Not contained
Attack vector
Plugin vulnerability
Admin access
Seized by attacker
Database state
Dumped & modified
Affected Resources
- /wp-admin/ — admin panelAccess hijacked
- wp_users — user tableCredentials dumped
- /wp-content/uploads/Webshell uploaded
- wp-config.phpDB credentials exposed
- contact-form-7 (plugin)RCE entry point
- .htaccessModified — redirects injected
Event Log
02:44:17CRITMalicious file upload via contact-form-7 — shell.php written to /uploads/
02:45:03CRITRemote code execution confirmed — shell.php accessed from 91.108.x.x
02:51:39CRITwp-config.php read — DB credentials harvested
03:02:14CRITFull wp_users table dumped — password hashes exfiltrated
03:18:50WARN.htaccess overwritten — visitors redirected to phishing domain
07:55:00INFOIncident response team notified — site taken offline pending review