Wordfence detects change in wp-admin/includes/upgrade.php

Search the Trac for these kinds of core changes:

Hata!: SQLSTATE[HY000] [1045] Access denied for user 'divattrend_liink'@'localhost' (using password: YES)