First thing I would do if I were in your shoes, is restore your latest database backup. After you do that, disable all plugins until you can identify which one is potentially being exploited (if in fact it is due to one of the mods). Also change yopur password for admin accounts, and lastly, double check the config.php file to make sure no users can run queries from within admincp.
|