wp-content/plugins/mystickymenu/mystickymenu.php
wp-content/plugins/mystickymenu/update.php
When I look at the modification date for these and all the OTHER files for this plugin, they are all the same: March 21, 2024 at 6:39 am on the production site and 6:12 am on the staging site (probably PDT time zone). The WordFence email alert for the production site says: “Alert generated at Wednesday 27th of March 2024 at 03:10:10 AM”. For the staging site it says: “Alert generated at Wednesday 27th of March 2024 at 03:10:28 AM”. Those alerts were created 6 days after the last automatic update for the plugin.
I contacted the My Sticky Bar (formerly My Sticky Menu) folks and they know of nothing that would have triggered this warning. Is this a false positive, or should I be concerned? The fact that I got the same warning for two sites with different domain names makes me suspect a false positive. The staging site was cloned from the production site many months ago, so the probability that malware caused the Wordfence warning for both sites on the same day seems unlikely. I also have a second test site I cloned from the same production site two or three weeks ago; I got the same alert for that site over a day later than the other two: “Thursday 28th of March 2024 at 10:19:19 PM”. Curiously, the last modified date on the files from that site are also a day later than for the other two sites: March 22, 2024 at 8:07 PM.
Should I be concerned? Is there anything else I should check?
]]>Today, I got a notification on my Wordfence firewall that says some files on license-manager plugin have changed.
i want to know if this is normal and its from license-manager team or its by attacker.
Here is the modified file list:
wp-content/plugins/license-manager-for-woocommerce/includes/AdminMenus.php
wp-content/plugins/license-manager-for-woocommerce/includes/Crypto.php
wp-content/plugins/license-manager-for-woocommerce/includes/Export.php
wp-content/plugins/license-manager-for-woocommerce/includes/Main.php
wp-content/plugins/license-manager-for-woocommerce/includes/Settings.php
wp-content/plugins/license-manager-for-woocommerce/includes/Setup.php
screenshots:
https://prnt.sc/2XgETQQeZ2Dl
https://prnt.sc/Y_ctiaNnC6K2
https://prnt.sc/J5fMJqGeNU37
my Plugin Version:3.0.4
]]>Wordfence is the latest version.
]]>I saw this – https://www.wordfence.com/privacy-policy/ . I want to be informed, what data where collected and why and how they where used, after I have deleted the plugin and by what right where my data collected if they where collected, since I have deleted the plugin? To inform you, I live in Greece, where GDPR is active and very much.
Thank you
]]>Thanks.
]]>For example, here’s one of the files that was modified:
coachkate/wp-content/cache/supercache/www.coachkate.com/how-to-lose-weight/top-ten-diets-to-try/index-https.html.gz
There are several others similar to this. I know for a fact I didn’t modify these files myself. However, at the bottom of the list it does say This list may include WordPress core/plugin/theme updates, error logs, cache files, and other normal changes.
Should I be worried? Is this suspicious activity?
Thanks in advance
Kate
]]>I recevied an alert about an modified file (wp-content/plugins/cache-enabler/inc/cache_enabler.class.php). Should I be worried?
]]>I have several plugins on various sites that have plugins that do not have support, or the author does not respond even after waiting for many weeks. I have issues with deprecated code, when I change the server PHP version. To keep using them I make changes to the lines with the deprecated code. As with the lax authors, who do not update their versions properly, I get warnings from Wordfence about the modified files.
I recently had warnings create_function()
deprecated in PHP 7.2 use anonymous function in a plugin. I changed the affected code on two different lines in the PHP file and the plugin continued to work properly, but without any warnings.
To my surprise, unlike with other similar code changes and even with high sensitivity running, I received no warning after scanning. Why?
]]>Since the update to version 2.3.4, Wordfence scan is showing warnings:
The following files belongs to plugin “Feed Them Social (Facebook, Instagram, Twitter, etc)” version “2.3.4” and has been modified from the file that is distributed by www.remarpro.com for this version.
Feed Them Social Version 2.3.4
Modified plugin files:
settings-page.css
feed-them-settings-page.php
feed-them-system-info.php
styles.css
youtube-feed.php
I assume that the last update did not show the changes in the version in the repository thus causing these warnings.
If only a few changes in a file, I can usually evaluate, if there is an issue. However, with so many files using minified code this is not feasible. Could you please update the files/version.
]]>