2023/01/31 22:58:14 [warn] 21606#21606: *77012759 a client request body is buffered to a temporary file /tmp/nginx_body_temp/0002341306, client: 46.147.61.69, server: indigo-models.com, request: "POST /wp-admin/admin-ajax.php?action=ai1wm_import HTTP/2.0", host: "indigo-models.com", referrer: "https://indigo-models.com/wp-admin/admin.php?page=ai1wm_import"
[Tue Jan 31 00:21:18.201846 2023] [:error] [pid 29496:tid 140343391500032] [client 167.235.25.176:51458] [client 167.235.25.176] ModSecurity: Warning. Operator EQ matched 8 at REQUEST_COOKIES. [file "/etc/httpd/mod_security/trustwave_rules.conf"] [line "3566"] [id "2500514"] [msg "SLR: WordPress Backdoored Plugins and Themes from AccessPress CVE-2021-24867"] [severity "CRITICAL"] [tag "CVE-2021-24867"] [tag "platform-multi"] [tag "attack-rce"] [tag "language-php"] [tag "application-WordPress"] [tag "https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-plugins-from-accesspress-themes/"] [hostname "indigo-models.com"] [uri "/wp-load.php"] [unique_id "Y9g0zkfsxyLFV95NCvaRDQAAAc8"], referer: www.bing.com
severity "CRITICAL"