Following yesterdays post about my sites being exploited by the “Cheap Pharma” a-holes, I was brought to the attention of another WP site (very popular in that) had similar issue too, Chris Pearson is the founder of DYI Themes, so I stated following his Twitter feeds to find help.

Per Chris, the exploit was in the DB, so just finding and replacing the file in the WP folder was not good enough, the DB needed to be cleaned as well. So here’s a how to:
For folks who regularly back up their sites, it would be much easier to do the fix as opposed to those who do no back up their site (another reason to use wp-db-backup plugin). Nevertheless there are ways to get the DB cleaned out. We will discuss both, but before we do that, here’s a step-by-step to find and remove the PHP file that is causing the havoc.
Use SimpleCode while including codes.
The links from all comments have the no-follow tag to prevent spammers from gaming their way up into SERP. So please keep the comments clean, try not to use keywords as "Names" or post unnecessary links in the comments. Thank you for cooperating.
Copyright © WP Pro – Design, Development and Professional WordPress Hosting for Serious Bloggers - CSS | XHTML | Login | Return to Top ↑
I had no idea that people could do this!! Jeez, it’s a jungle out there. I will definitely be using that backup plugin now – thanks!
I agree with this post as backups are certainly important. I’ve come across a situation similar to this that put our business back a whole week due to not properly backing up our servers. Take advantage of any automated tools – they’re worth it..even if you need a quick fix.