Wordpress spam problem
Ambimama.com has been severely hit by spam this month. I am guessing it is due to vulnerabilities in Wordpress blog application or Wordpress theme or maybe wordpress plugins.
My web hosting company sent me a report stating that bandwidth utilization in my wordpress based blog has increased by 300% month on month between April 2008 to May 2008. While traffic to my website has actually dropped by 30% during the same time frame.
How is this even possible?
I spent about 2 hours this morning investigating on Wordpress settings and other places. I finally figured out that the problem was due to someone inserting malicious pingback and other links in to my wordpress theme code.
Some one had edited my almost spring theme and had inserted more than 10,000 ping back links in to some porn website. Obviously, someone is trying to steal the page ranks away from my pages and possible redirecting traffic.
This could be due to my wordpress password getting cracked or maybe the theme I used was already modified with a malicious link back. Or maybe some of my wordpress plugins had vulnerabilities in them.
Anyways, I got it all figured out now and have fixed it. Hoping this doesn’t happen again. I have disabled comments altogether for the rest of my month at ambimama.com.
This has hit hard on my website bandwidth utilization for this month and am going to have to pay my webhosting company some money maybe toward for excess bandwidth usage. Wish internet was a better place. Hmmm, Anyways keeping my fingers crossed and hoping this doesn’t happen again.
Make sure you harden your wordpress control panel password, wordpress themes, wordpress plugins and keep a close watch on your theme PHPs.

