I manage a Wordpress site for an event registration. The site is only active for a few months a year. The rest of the year it's idle, as in it's up, but not actively maintained.
Now the time has come to prepare it again, and I noticed that all posts and pages have been edited. At the bottom of each page/post a script tag has been added. This tag creates a link to some website, if often links to domyhomework.com
, or something similar.
All these edits was made by the same user thats only a "publisher", and not an administrator. It is clear that this user did not actually do this, but it's also clear that his account was used. The edits all happened on the same date, from 11:51 to 11:54.
I have changed the password for the user, as well as "log out all other sessions". I've also installed a more solid activity logger, that will monitor the site from now on.
I'd like to know what exactly has happened here, so that I can prevent it in the future.
edit: It feels like the user has malware on his computer and when logged into the site a script runs and adds this to pages/posts, but I don't know how to prevent something like that, or if that is possible.