WordPress Security Expert Needed — Persistent Cloaked Spam Injection (Urgent) - Project

Cliente Freelancer · Remoto · Remoto · freelance · mid · 30–250 AUD

Publicada el 2026-07-20

Descripción de la oferta

My WordPress site has a recurring malware infection that injects hidden, cloaked spam links into a subset of published articles. This is a repeat infection — a previous, different malware issue (backdoors, rogue admin accounts, fake plugins, cloaking injector) was fully remediated a few months ago. This is a new/returned issue on the same site. I need an experienced WordPress security specialist to locate the actual injection mechanism, remove it completely, and harden the site against recurrence. I've done substantial diagnostic work myself already (detailed below) to save you time — please read it before quoting, as it rules out a lot of the usual suspects. What's Happening Hidden HTML is being inserted into the page immediately after , before the main content div, on a subset of published blog posts (not sitewide). The injected HTML uses overflow:hidden;height:1px; cloaking — invisible to normal visitors, visible to search engines and in "View Page Source." Contains spam links to sites.google.com/cryptowalletextensionus.com/ledger-live-download/ and polymarketau.at / polymarkets.at (destination domain rotates slightly between pages). Confirmed affected pages found A fully hidden spam post (ID 402722, "Choosing a Binance-integrated Web3 wallet for DeFi...") was found published since Dec 7, 2025 — invisible to wp-admin's normal post search despite being a standard post type. Already moved to draft by me. What I've Already Ruled Out (please don't re-check these first) Not stored in the database as text — confirmed via direct SQL search across post_content, Elementor's _elementor_data, and all postmeta fields for the affected posts. Zero matches anywhere. Theme is clean — checked and confirmed stock/unmodified: child theme functions.php, parent theme (Hello Elementor) functions.php, header.php, and theme.php. mu-plugins — only file present is the standard WPMU DEV hosting-compatibility file (legitimate, verified). Code Snippets plugin — 5 saved snippets found, all confirmed inactive, all reviewed and harmless (an unfinished Google Analytics placeholder among them). Drop-ins — both advanced-cache.php (inactive/unused) and object-cache.php (WPMU DEV's own Memcached object cache) appear to be standard hosting infrastructure, not malicious. Removed several plugins already after running Defender Pro's file malware scan, which flagged them (including one called "Track The Click" with no identifiable publisher). Injection persisted after removal. Cache is not the cause — cleared Hummingbird page cache repeatedly; injection persists. Have not yet been able to confirm/rule out a Memcached object-cache flush specifically (this may still be masking a real fix — worth checking early). What This Points To Since the spam text doesn't exist anywhere in the database and the theme is clean, this is almost certainly generated live by PHP at render time — likely a backdoor file, a webshell, or malicious code hooked into the_content or a similar filter from an active plugin we haven't isolated, or a file sitting outside the normal plugin/theme structure (e.g. in /wp-content/uploads/ or site root). Possibly condition-based (triggers on specific post IDs, categories, or a pattern I haven't identified). Scope of Work Full server-level malware/file scan (diff against known-clean plugin/theme versions), not just a database-level check. Identify and remove the exact file(s)/code responsible for this injection. Check for and close the access point that allows this to keep recurring (rogue admin account, backdoor, compromised plugin, exposed API endpoint, etc.) — this is a repeat infection, so the root access point from before may not have been fully closed. Confirm removal by verifying clean "View Page Source" on all previously affected articles, post cache-flush (including any object cache / Memcached / CDN layer). Check Google Search Console for Security Issues flagged during the infection period and advise on requesting a review once clean. Provide a short written summary of what the root cause was and what hardening steps were taken (firewall rules, file permission changes, plugin/account audit, etc.). Environment Details WordPress, Elementor + Elementor Pro (site is heavily built with Elementor), Hello Elementor theme + child theme. Hosting: WPMU DEV managed hosting. Security plugin already installed: Defender Pro (WPMU DEV). Access will be provided via WPMU DEV hosting dashboard / SFTP / wp-admin as needed. Ideal Freelancer Proven experience specifically with WordPress malware removal / cloaking injection cases, not general WordPress development. Comfortable working directly with SFTP, server file scans, and raw database queries (phpMyAdmin/Adminer). Can explain findings in plain English, not just "fixed it" — I want to understand what happened. Please include examples of similar cloaking/spam-injection cases you've resolved before, if you have them. Note This is a live, revenue-generating business site — please avoid deactivating plugins in bulk or making broad changes without checking in first, as I don't have WordPress development experience myself to fix any breakage that results.

Skills

Fuente original: freelancer

Análisis JobHunter