WordPress Incident Response - Backdoor & Credit-Card Skimmer Removal + Avada RCE Hardening
Employer not named by the sourceRemote
Frontier is not the employer and does not collect applications.
About this role
PHP, Web Security, WordPress, Internet Security, phpMyAdmin, Website Optimization, Firewall, cPanel, Incident Response, Security Auditing · My WordPress site, running the Avada theme, has started acting strangely and deeper checks revealed both a backdoor and a credit-card skimmer hiding in the code. I have not made any recent updates or configuration changes, so the intrusion is likely exploiting an Avada-related RCE vulnerability.
I need a security-focused WordPress specialist to investigate, clean, and then harden the installation so the issue cannot recur.
Core tasks and deliverables • Locate and remove every malicious file, injected script, hidden admin user, and rogue database entry. • Verify and, if needed, safely reinstall WordPress core plus the Avada theme to guarantee integrity. • Patch and harden against known Avada remote-code-execution vectors: correct file permissions, disable unused endpoints, regenerate salts, secure wp-config, and lock down uploads. • Implement ongoing protection—firewall/WAF rules, real-time malware monitoring, and scheduled scans—without affecting site performance or design.
Acceptance criteria • Wordfence or Sucuri scans return 0 critical or high-severity issues. • No outbound calls to unknown domains on checkout or any other page. • Server logs stay clean for 24 hou