Quantcast
Channel: WordPress.org Forums » [Wordfence Security - Firewall, Malware Scan, and Login Security] Support

WordPress site hacked

$
0
0

Replies: 0

My site was hacked and If I access to the site. It shows hackers’ screen.
It shows only this screen even I input any url.
For example, /aaaaaaa also shows this screen.
I want to find malware code and remove it.
How can I find?


Duplicate rules

$
0
0

Replies: 0

Hi,

While checking my .htaccess file I came across these values added by the Wordfence plugin in:

# Wordfence WAF
<IfModule LiteSpeed>
	php_value auto_prepend_file '/home/u864865843/domains/xyz.com/public_html/wordfence-waf.php'
</IfModule>
<IfModule lsapi_module>
	php_value auto_prepend_file '/home/u864865843/domains/xyz.com/public_html/wordfence-waf.php'
</IfModule>
# END Wordfence WAF

I’m using LiteSpeed plugin and not sure if these are duplicate rules. Should I keep both or remove one but which one?

ERROR: An error was encountered while trying to authenticate. Please try again.

$
0
0

Replies: 0

ERROR: An error was encountered while trying to authenticate. Please try again.

Can’t login my WordPress Dashboard Account

Please help me. Please please please

  • This topic was modified 5 hours, 35 minutes ago by mdtarik.

No able to edit Elemento after Wordfence

$
0
0

Replies: 0

Hello! I installed Wordfence and suddenly Edit with Elementor option disappeared. I deleted Wordfence but the issue persists. I hope you can help me. Thanks!

Whitelist Background Request

$
0
0

Replies: 0

I have some trouble getting Wordfence to allow a Background Request, it does ask if I want to whitelist it but if I say yes and try again it is still blocked.

More specific I try to use the plugin SmartCrawl by wpmudev, but word fence blocks the “save changes” and dosen’t seem to stop blocking it when whitelisting it

  • This topic was modified 2 hours, 19 minutes ago by wiezo.

ERROR: Apache to Litespeed migration

$
0
0

Replies: 0

I’m migrating servers from Cloudways, which uses Apache, to xCloud. I’ve selected Litespeed for my host there.

The migration works fine.

WordFence prompts me to update my .htaccess file. If I do that, then my site no longer loads.

Instead, a visitor gets prompted to download a file.

I can restore to get it working, but them I’m stuck with messages telling me that I’m not optimized by WordFence for Litesped.

What would be the resolution to update my .htaccess without screwing up my website?

Always 2 attempts to login to site admin

$
0
0

Replies: 0

Just lately (last 2 months or so), it always takes me two attempts to login to our site as admin.

We’re running WordFence with 2FA on my admin login. The username and password is saved in my browser, so it is the same each time.

Typically, username and password is auto-entered by the browser with fingerprint ID and I type in the 2FA from the Authy app on my phone. I always get an error on the first attempt (invalid username or password) and it works on the second attempt.

WordFence then lists my unsuccessful attempts in its dashboard, with Yes under Existing User.

I can’t see that I’m doing anything wrong or even different – but I’m worried I might eventually get locked out!

This has only been an issue lately, so I wonder if it might be as a result of something in a recent update.

Anyone else having the same issue?

Any suggested fixes or trouble-shooting?

Blank htaccess file twice in two days

$
0
0

Replies: 0

I have a clients site that twice in two days has had issues with the htaccess file being completely erased resulting in 404 errors when customers try navigate around the site. The home page loads but not the internal pages.

Can anyone suggest any trouble shooting hints to resolve this?


Scan says up-to-date plugin needs updating.

$
0
0

Replies: 0

The Plugin “Restrict Content Pro” needs an upgrade (3.5.41 -> 3.5.41). Type: Plugin Upgrade

WordFence Version 7.11.5, WP version 6.5.2.

Edit: After a while, the message has gone.

I want to get a free license of Wordfence plugin

$
0
0

Replies: 0

Hello,
I am a WordPress user for several years. Currently i want to install Wordfence plugin for free.
Please help me to solve this as early as possible.
With regards,
Rezaul Karim

How do I Block Google Bot Crawling Non Existent Images

$
0
0

Replies: 0

I have multiple pages that google is trying to call with non existent images how do I block them and any future ones using WordFence please?

I also have 404 errors which are the requests from Visualsoft-Monitoring (previous website) that tries to search for some non-existing file in the .well-known directory:

“Error reconnecting to the database” on limited scan

$
0
0

Replies: 0

Hello, we re trying to run Wordfence scan on our web site – 5 subsites WPMU installation on dedicated Linux server with fair amount of content. First we’ve got the same error on normal scan, after that tried to switch to limited scan to see if it will make a difference. This got us a little bit further but still ended with

Error reconnecting to the databaseThis means that the contact with the database server at localhost was lost. This could mean your host’s database server is down. Are you sure the database server is running? Are you sure the database server is not under particularly heavy load? If you are unsure what these terms mean you should probably contact your host. If you still need help you can always visit the WordPress support forums.

There were no database server load problems or connection problems at the time.

What steps do we need to take to be able to run normal scan on our site?

License not activated

$
0
0

Replies: 0

Hello

The license is not getting activated for some reason and asking me to reach out to help. Tried manual activation as well as email link – click. Same result.

Live traffic is now unspecified

$
0
0

Replies: 0

I just built a new wordpress site and added wordfence. On my old site, the “Live Traffic” page of wordfence showed the country of origin of each IP. My new site just lists “unspecified” as the country.

Has this feature been removed? Is this a bug?

Login Verification Required

$
0
0

Replies: 0

I am the admin for my website. All of a sudden I can’t log in without responding to a email verification. The email states “request was flagged as suspicious, and we need verification that you attempted to log in to allow it to proceed.” I created this site and haven’t had this issue before. Whitelisted my IP but that didn’t help. Captcha has been on for years. Very frustrated.


Blocking file upload

$
0
0

Replies: 0

I was trying to upload files with name like “Applying-Conflict-Management-Skills-at-Workplace.pdf” but WordFence is returning the following error (for a non admin role)…

“A potentially unsafe operation has been detected in your request to this site. Your access to this service has been limited. (HTTP response code 403)”

how can we overcome this? if i add the param to firewall allowlist, will wordfence still able to detect any potential malicious file being uploaded via this plugin?

I cannot delete the allowed IP

$
0
0

Replies: 0

Hi

I had a website hack, after cleaning all the files I had another hack.

While looking for a solution, I came across the setting “Allowed IP addresses that bypass all rules” – and here I cannot delete the existing IP address – 141.94.254.72.
I suspect that this is the cause of another hack, how can I delete this IP and remove the problem of entering this IP on the allowed list?

thank you

Customize 403 Page

$
0
0

Replies: 0

Hello – How is the Wordfence 403 page customized? I would like to update the text on this page.

Thanks

Allow / Whitelist by user-agent

$
0
0

Replies: 0

Hello, is there a way to allow or whitelist a user-agent? I use Siteguru for SEO as an SEO tool, and it returns many 403 errors for internal links while these links return a 200 when I run an status check with another tool. It’s fixed when I deactivate WordFence.

SiteGuru uses the user agent SiteGuruCrawler which I would like to whitelist, but I can’t find an option for that.

Thanks
JP

502 Bad Gateway

$
0
0

Replies: 0

I logged off at 5 PM yesterday and around 6 PM the files in the wflogs and the plugin folder show modified. This morning we are all getting 502 Bad Gateway when we try to access the site. I am able to FTP to the file system and check the files but can’t figure out what changed or why. This is on NGINX not Apache so there is no .htaccess file but I did add some IP restrictions to the WordFence and blocking all bots in the Robots.txt file recently because some static content was appearing on Google searches even though the site is password protected (in development). How do I see what was changed/why and fix this?

Server IP being blocked massively

$
0
0

Replies: 0

Our server IP is a clean IP, and we only have a few personal and business sites etc.

Recently in the last 2 months our website and all our clients using WordFence are showing our server IP being blocked dozens and hundreds of times. We even have XML RPC closed down on Apache.

Why is WordFence blocking and flagging our server IP? This is a big problem and I have no idea how to fix it, and the previous threads on this showed the issue unresolved. Please help.

Scan fails repeatedly

$
0
0

Replies: 0

The website in question is hosted at InMotion Hosting. Standard scan has consistently failed for weeks. I have tried all of your troubleshooting tips (including wp-config.php tweak). I sent a report and an activity log to wftest@wordfence.com.


“CAPTCHA EXPIRED” issue

$
0
0

Replies: 0

Hello,

We have been getting the error message when trying to login:
CAPTCHA EXPIRED: The CAPTCHA verification for this login attempt has expired. Please try again.

We have tried these steps with no success:

  • Uninstalling and reinstalling Wordfence
  • Disabling every plugin except Wordfence and defaulting to the default theme.
  • Getting new reCAPTCHA keys from Google
  • Trying different score numbers.

We are running 6.5.2 for WP and 7.11.5 for WF.
Any help would be appreciated.

Unable to login (admin-ajax.php) error 400

$
0
0

Replies: 0

Hi, I don’t know if my issue could be related to Wordfence, but, since some time ago, I’m unable to login as administator into my site.

I receive a 400 error:

https://www.osg2001.it/wp/wp-admin/admin-ajax.php 400 (Bad Request)

I’m the only admin in this site and I didn’t made any changes since all works fine (I always use the 2FA with Wordfence).

I tried to disable all pluging, all themes, but nothing changes, of course I cannot use Wordfence, due I’m unable to get into admin section of my site.

Despite this the site is reachable online, only the admin section is unreacheable.

Do you have any idea about this ? I end ideas…

Thank you very much for any suggestion

Not able to scan

$
0
0

Replies: 0

  • Scan FailedThe scan has failed because we were unable to contact the Wordfence servers. Some sites may need adjustments to run scans reliably. Click here for steps you can try.(opens in new tab)The error returned was:There was an error connecting to the Wordfence scanning servers: cURL error 35: OpenSSL SSL_connect: Connection reset by peer in connection to noc1.wordfence.com:443
  • At the time of scan above error received
  • This topic was modified 1 hour, 52 minutes ago by minaxi11.

admin-ajax.php 404 (Not Found)

$
0
0

Replies: 0

Hello there,

Recently i am encountering an issue on my website as am not able to save setting in wp-admin/customize.php

Everytime am trying to save css, it is giving me Looks like something’s gone wrong. Wait a couple seconds, and then try again.

While inspecting i found the following error :

Failed to load resource: the server responded with a status of 400 (Bad Request)

/wp-admin/admin-ajax.php

POST /wp-admin/admin-ajax.php 404 (Not Found)
jquery.min.js?ver=3.7.1

I tried to disable all plugins except Wordfence and am still getting the error.

So, i suspect the issue is with Wordfence. I have sent you the diagnosis under the name jeeya1609.

Your assistance will be helpful.

Regards,

Jeeya

A Lot of Failed Login Attempts

$
0
0

Replies: 0

I just setup Wordfence and i’m getting alot of “failed login” attempts on the traffic log. These login attemps are with the admin usernames.

I started manual IP Blocking, and manually permanently blocking these IP’s but here is the funny part: I got locked out of my own website, and i had to send the confirmation e-mail to unlock myself…

I din’t do any failed login attempts, as my admin account logs in automatically. So what gives? I am 100% certain i only banned IP’s that had failed login attempts.

Unusual Visitors After Installing Wordfence

$
0
0

Replies: 0

Good Afternoon,

The day after installing wordfence, i’ve been getting visitors from unusual countries like india, colombia, and some african countries.
It’s a portuguese website, intended mainly for a portuguese/european audience and i don’t get why wordfence had this effect on the visitors.

Any thoughts? I’m afraid installing wordfence has put my website on a target list, because i’ve also been getting weird admin login attempts.

Has anyone experienced this? Thank you in advance

Infinite loop installing free license

$
0
0

Replies: 0

Hi

We have been using Wordfence on most of our ~340 sites for a couple of years, which has worked well. A few weeks / months ago, we started getting this warning: “Wordfence installation is incomplete”

When clicking resume installation, we need to get a free license, which we get per email. Then We install the license, it says “Congratulations” and successfully installs the license. However, when going to the dashboard or anywhere else in wp-admin, the message comes back: “Wordfence installation is incomplete”.

This happens in an infinite loop, and there doesn’t seem to be possible to remove the warning.

This seems to happen on all our websites.


Consistent warning about malicious code but the code is not there

$
0
0

Replies: 0

Hi,
I get a scan warning that the file has malicious code (theme functions.php file) but when I download the file and search for that code from Wordfence report the code is not there.
What can be the issue?
The code is:
Details: This file appears to be installed or modified by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The matched text in this file is: function widget_text_exec_php( $widget_text ) {\x0aif( strpos( $widget_text, ‘<‘ . ‘?’ ) !== false ) {\x0aob_start();\x0aeval( ‘?>’ . $widget_text );\x0a$widget_text = ob_get_contents();\x0aob_end_clean();\x0a}\x0areturn …





Latest Images