Many sites were hacked and injected with forwardmytraffic malicious script, despite using Wordfence. In most cases, there’s no admin access – wp-admin […]
We’ve been fixing lots of sites lately, which have siteurl value changed to either: hxxps://mytemplatewebsite[.]com/0.js hxxp://wtools[.]io/code/raw/so? hxxp://erealitatea[.]net hxxp://blueeyeswebsite[.]com/ad.js