Our website has been breached multiple times. Now we even found a backup.zip in a public path and still can not find the backdoor.
Flag format: ctf{sha256}
CTF{87702788126237df9c4a915fea9441345dc6b3a0272b214b2c31e50a8f89c4b1}
Found the backdoor written in the ‘functions.php’ file of the current WordPress theme, then used it to get the flag.
Basically, hackers write their backdoors in the “functions.php” file of the wordpress theme, as it is responsible for calling native PHP, WordPress, and other functions. So, it can be used to perform any kind of operation.
This little guy was hiding there (wp-content/themes/twentytwentytwo/functions.php):
So, I used this backdoor to get the flag (notice the URL):
More info about WordPress backdoors here: https://www.wpbeginner.com/wp-tutorials/how-to-find-a-backdoor-in-a-hacked-wordpress-site-and-fix-it/.