I've found a unwanted file in my wp-content/themes/ folder with the name of signups.php.
It showed my phpinfo and would be able to send out spam-mails.
Wordfence did not find it, even when comparing core files etc.
Is this normal behaviour?
I've found a unwanted file in my wp-content/themes/ folder with the name of signups.php.
It showed my phpinfo and would be able to send out spam-mails.
Wordfence did not find it, even when comparing core files etc.
Is this normal behaviour?