Yesterday I had to fix a Wordpress which suddenly stopped responding only to the login requests, while everything else was working fine. Turned out that a mail plugin was making PHP hang on a SMTP call because the configured mail server wasn’t responding 🫠
That site called for help again. One of the accounts was compromised and the attacker activated a theme and some plugins that were injecting a JS in all pages. The JS was showing a fake captcha asking for validation by using the terminal and pasting something. It was a pain to find and remove all the trash, but I believe (hope) I did clean it completely 🤞