WordPress Incident Response - Backdoor & Credit-Card Skimmer Removal + Avada RCE Hardening
Budget / Salary£250–750
TypeFreelance project
LocationRemote
Posted2 hours ago
My WordPress site, running the Avada theme, has started acting strangely and deeper checks revealed both a backdoor and a credit-card skimmer hiding in the code. I have not made any recent updates or configuration changes, so the intrusion is likely exploiting an Avada-related RCE vulnerability.
I need a security-focused WordPress specialist to investigate, clean, and then harden the installation so the issue cannot recur.
Core tasks and deliverables
• Locate and remove every malicious file, injected script, hidden admin user, and rogue database entry.
• Verify and, if needed, safely reinstall WordPress core plus the Avada theme to guarantee integrity.
• Patch and harden against known Avada remote-code-execution vectors: correct file permissions, disable unused endpoints, regenerate salts, secure wp-config, and lock down uploads.
• Implement ongoing protection—firewall/WAF rules, real-time malware monitoring, and scheduled scans—without affecting site performance or design.
Acceptance criteria
• Wordfence or Sucuri scans return 0 critical or high-severity issues.
• No outbound calls to unknown domains on checkout or any other page.
• Server logs stay clean for 24 hours after hand-off, with no suspicious cron jobs or processes.
You will receive cPanel, SSH, phpMyAdmin, and WP-admin access. I’m aiming for a 24- to 48-hour turnaround, but let me know if you need a different window so we can coordinate downtime.
I need a security-focused WordPress specialist to investigate, clean, and then harden the installation so the issue cannot recur.
Core tasks and deliverables
• Locate and remove every malicious file, injected script, hidden admin user, and rogue database entry.
• Verify and, if needed, safely reinstall WordPress core plus the Avada theme to guarantee integrity.
• Patch and harden against known Avada remote-code-execution vectors: correct file permissions, disable unused endpoints, regenerate salts, secure wp-config, and lock down uploads.
• Implement ongoing protection—firewall/WAF rules, real-time malware monitoring, and scheduled scans—without affecting site performance or design.
Acceptance criteria
• Wordfence or Sucuri scans return 0 critical or high-severity issues.
• No outbound calls to unknown domains on checkout or any other page.
• Server logs stay clean for 24 hours after hand-off, with no suspicious cron jobs or processes.
You will receive cPanel, SSH, phpMyAdmin, and WP-admin access. I’m aiming for a 24- to 48-hour turnaround, but let me know if you need a different window so we can coordinate downtime.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.