Dalood

In collaboration with Plexygon.com

Task : Dalood is a Georgian fashion brand with an online store built on WordPress/WooCommerce. The site went down after a critical database failure: orders could not be placed, the admin panel was unstable, and the database was corrupted at the table level. At the same time, a massive bot attack was discovered — over 3,400 fake accounts. An XSS vulnerability in the WoodMart theme (CVE-2025-47600) was also identified. The goal was to restore the store, clean up the database, and protect the site from future attacks.

Solution : Since the original database was corrupted, migrating it as-is would have carried the problems over. The decision was made to rebuild the site on a clean installation, migrating only the content. A dev server was set up on a subdomain with DNS configured through Cloudflare, and a fresh WordPress install with WoodMart and WooCommerce was deployed. A catalog of 328 products with variations and images was exported and imported into the new site. Over 1 GB of media files were transferred via cPanel, with URLs replaced in the import files to avoid redundant downloads. Users were migrated separately with password hashes preserved, along with order history. Multi-currency support was restored through WPML. Custom SQL queries were written to identify and remove 3,426 fake bot accounts without affecting real customers or administrators. A WooCommerce order sync issue (HPOS) that was preventing new orders from being created was resolved. The WoodMart theme was updated to patch the XSS vulnerability. Cloudflare WAF was configured with blocking rules.

Outcome : The store was fully restored and relaunched on a clean, stable infrastructure. The database was purged of junk data, the checkout process is fully operational, and the site is protected against bot attacks. The client received a working store with no loss of products, orders, or customer data.

Other Works