Viewing 6 replies - 1 through 6 (of 6 total)
  • This is probably inserted through a plugin or an individual adaptation of the theme. As a test, deactivate all plugins and also change the theme. Once it’s gone, deactivate it little by little until you find the cause.

    tonydotigr

    (@tonydotigr)

    Were you able to figure out what was causing the code injection with that site? We have the same problem in the header.

    threadi

    (@threadi)

    edwrys

    (@edwrys)

    The url is in this location, in the jquery_js_for_specific_pages method, it is in base64

    • wp-content\plugins\cloudflare-flexible-ssl\plugin.php
    • Method: jquery_js_for_specific_pages
    • Var: $encoded_url = ‘aHR0cHM6Ly9hcGlkZXZzdC5jb20vSllDd1U0YkZoc0xDZ2VmSnZSVlo3VVFhM25QQVdxNEYteExpU0NoWUJq’;

    tonydotigr

    (@tonydotigr)

    Thank you, guided me down the right path to find the reference that was injecting the code. The spot was not the same, but similar.

    I keyed on some of the elements you mentioned with ‘String Locator’ and found referenced to a plugin called ‘Fusion Optimizer Pro’. This was adding the code reference.

    Thread Starter kaspyder

    (@kaspyder)

    @edwrys Thank you for sorting me out. It worked out 100%. My nightmare is over!

    • This reply was modified 9 months ago by kaspyder.
Viewing 6 replies - 1 through 6 (of 6 total)
  • The topic ‘need help disabling a script that is in my wordpress header’ is closed to new replies.