My security software has found this in your plugin.
Severity: enMaliciousThreatType File: wp-content/plugins/coupon-creator/plugin-en/…/release.php File signature: 644157a15a215f5cbb5767d53233a088 Threat signature: 9774ea3e7fcdd3eabf389fd24b64f645 Threat name: Backdoor.PHP.Exec.gen.3CE Threat: <?php /** * Rele Details: Detected malicious PHP code
I have removed it straight away as it detected it as SEVERE issue.
I can’t afford to have my client site infected by malware.
Unless this is a false positive but I assume not ?
Please advise the steps you take to FIX your plugin that has been compromised if it has been?
Thanks
Kristin
]]>I’m using your plugin. I had a site had a few dodgy files found on the client site. Some dodgy files in Storefront directory and within your cache directory.
I’ve installed Wordfence also to do some scanning and finding all dodgy files to remove them etc.
The scan came up with a few dodgy files in the cache directory in wordpress. So I removed your plugin entirely which I thought would fix it. I’ve removed the affected file in Storefront also (only 1)
Then I reinstall your plugin, and activate it, then some new different dodgy files appear in that cache directory under the wp-includes after installing your plugin.
So I’m trying to figure out HOW to fix it, find all files that are causing it. Not sure HOW or WHY it is coming directly into that directory of your plugin when I reinstall it completely.
Do you have any suggestions that can help please?
All suggestions and help would be greatly appreciated.
Thanks
Kristin
]]>I’ve installed Wordfence on a client site.
Wordfence seems to have picked up some dodgy files in Storefront on client site. Wordfence has picked up in storefront/assets/images/credits-cards/elastic-slider.php
and storefront/asets/images/admin/welcome-screens/wpzhijdengl.php which I assume are dodgy files.
..storefront/assets/images/customizer/starter-content-products/hoodie-with-zipper.php (seems dodgy also).
What about this one: storefront/assets/images/admin/welcome-screen/automattic.php ? Should that be there or dodgy ? Is there supposed to be an actual welcome-screen directory?
Seems to be some additional php flies that shouldnt’ be there in those directories ..
Can I just delete ALL files under the credit-cards directory, do I need them? I would rather delete if I can to remove the dodgy files,.
And it says this file is unsafe wp-content/themes/storefront/functions.php – CRITICAL
Especially under Storefront assets
Here is 1 error log
[18-Sep-2023 02:24:09 UTC] PHP Notice: Undefined offset: 0 in domain.com.au/wp-content/themes/storefront/assets/images/credit-cards/elastic-slider.php on line 1 [18-Sep-2023 02:24:09 UTC] PHP Warning: shell_exec(): Cannot execute a blank command in domain.com.au/wp-content/themes/storefront/assets/images/credit-cards/elastic-slider.php on line 1 [17-Jun-2024 01:59:01 UTC] PHP Notice: Undefined offset: 0 in domain.com.au/wp-content/themes/storefront/assets/images/credit-cards/elastic-slider.php on line 1 [17-Jun-2024 01:59:01 UTC] PHP Warning: shell_exec(): Cannot execute a blank command in domain.com.au/wp-content/themes/storefront/assets/images/credit-cards/elastic-slider.php on line 1
Storefront is at its latest version 2.4.6 (is that the latest version ?) so I cannot tell what directories or files are supposed to be there and which ones are dodgy files within STorefront files. There is no option to upgrade STorefront so I assume that is current version.
Website seems to have been partly compromised so I’m trying to find the dodgy files. Wordfence plugin is great at letting me know which files to look at that could have issues.
Can someone help and advise please on what is safe to REMOVE that shouldn’t be there in the STorefront files and directories please?
Is there somewhere I can look and compare what directories/files should be there and not be there?
Thanks Kristin
]]>I recently launched my new website. However, I was not expecting a million issues. First, my website does not show properly at all anywhere except when I am logged. When I am not logged in, everything is beyond terrible and not what I set it to be. For background, I am using Elementor, Elementor Pro, and the free version of the Astra Theme.
Secondly, my product (Woocommerce is used for this) and blog thumbnails don’t show on mobile at all.
A few days ago the “add to cart” button and payment buttons were not working. I switched the PHP version from 8.1 to 7.4. Switching to 7.4 fixed those issues, but maybe it caused all these other major issues I am having.
Also, I have a lot of plugins, so maybe this has something to do with it. I have:
If at all, what plugins should I delete, and would it help with my website issues?
]]>strange issue: when i copy a style with the new wp 6.2 function and want to apply it to another section in a blog post or page I get this error message:
“The styles could not be inserted. Please activate the permissions for the
use of the browser clipboard before you continue.” ( translated from german to engl, because my worpress is a german version)
Does anyone knows whre to “activate a permission for the use of browser clipboard” Never saw this before in wordpress:
Best
Chris
& when I checked the error , error is
Warning: require(/home/iovda6cs/public_html/wp-blog-header.php): failed to open stream: No such file or directory in /home/iovda6cs/public_html/index.php on line 20
Fatal error: require(): Failed opening required ‘/home/iovda6cs/public_html/wp-blog-header.php’ (include_path=’.:/opt/alt/php74/usr/share/pear’) in /home/iovda6cs/public_html/index.php on line 20
I am able to access my WordPress dashboard but I am unable to access my website.
can anyone assist me with this, please?
Thanks.
]]>