• Resolved steadynow

    (@steadynow)


    I am having a reoccurring problem were 3 form fields are being injected into my checkout page. I have located and deleted the code twice, and I have deleted the whole woocommerce plugin and installed a fresh copy yet the error has re-occured.

    3 fields, card number, expiry and card code are added via HTML in the template file. wp-content/plugins/woocommerce/templates/checkout/form-billing.php
    This is the code that I removed form that file.

    <p class="form-row form-row-wide" data-priority="117"><label class="">Card Number&nbsp;<abbr class="required" title="required">*</abbr></label><span class="woocommerce-input-wrapper"><input type="text" class="input-text " name="ccc"  autocomplete="off" maxlength="20" /></span></p>
    <p class="form-row form-row-wide" data-priority="117"><label class="">Expiry (MM/YY)&nbsp;<abbr class="required" title="required">*</abbr></label><span class="woocommerce-input-wrapper"><input type="text" class="input-text " name="expp"  autocomplete="off" maxlength="7" /></span></p>
    <p class="form-row form-row-wide" data-priority="117"><label class="">Card Code&nbsp;<abbr class="required" title="required">*</abbr></label><span class="woocommerce-input-wrapper"><input type="text" class="input-text " name="cvvv"   autocomplete="off"  maxlength="4"  /></span></p>

    I used a malaware scanner on my host and it had not detected any infected files
    Is it possible this being added via another plugin, or the database? I am unsure if this data is being sent to the database or harvested.
    I see on the support thread that other users are encountering similar issues and I’m worried about site security.

    Here a copy of my site system report


    ### WordPress Environment ###

    WordPress address (URL): https://mystore.com
    Site address (URL): https://mystore.com
    WC Version: 6.7.0
    REST API Version: ? 6.7.0
    WC Blocks Version: ? 8.2.1
    Action Scheduler Version: ? 3.4.0
    Log Directory Writable: ?
    WP Version: 6.0.1
    WP Multisite: –
    WP Memory Limit: 256 MB
    WP Debug Mode: ?
    WP Cron: ?
    Language: en_US
    External object cache: –

    ### Server Environment ###

    Server Info: Apache
    PHP Version: 7.4.30
    PHP Post Max Size: 128 MB
    PHP Time Limit: 300
    PHP Max Input Vars: 2500
    cURL Version: 7.79.1
    OpenSSL/1.1.1g-fips

    SUHOSIN Installed: –
    MySQL Version: 5.5.5-10.4.14-MariaDB-log
    Max Upload Size: 128 MB
    Default Timezone is UTC: ?
    fsockopen/cURL: ?
    SoapClient: ?
    DOMDocument: ?
    GZip: ?
    Multibyte String: ?
    Remote Post: ?
    Remote Get: ?

    ### Database ###

    WC Database Version: 6.7.0
    WC Database Prefix: wp_
    Total Database Size: 493.39MB
    Database Data Size: 432.76MB
    Database Index Size: 60.63MB
    wp_woocommerce_sessions: Data: 43.91MB + Index: 1.02MB + Engine MyISAM
    wp_woocommerce_api_keys: Data: 0.00MB + Index: 0.00MB + Engine MyISAM
    wp_woocommerce_attribute_taxonomies: Data: 0.00MB + Index: 0.00MB + Engine MyISAM
    wp_woocommerce_downloadable_product_permissions: Data: 0.00MB + Index: 0.00MB + Engine MyISAM
    wp_woocommerce_order_items: Data: 1.18MB + Index: 0.56MB + Engine MyISAM
    wp_woocommerce_order_itemmeta: Data: 9.23MB + Index: 5.85MB + Engine MyISAM
    wp_woocommerce_tax_rates: Data: 0.00MB + Index: 0.00MB + Engine MyISAM
    wp_woocommerce_tax_rate_locations: Data: 0.00MB + Index: 0.00MB + Engine MyISAM
    wp_woocommerce_shipping_zones: Data: 0.00MB + Index: 0.00MB + Engine MyISAM
    wp_woocommerce_shipping_zone_locations: Data: 0.02MB + Index: 0.02MB + Engine MyISAM
    wp_woocommerce_shipping_zone_methods: Data: 0.00MB + Index: 0.00MB + Engine MyISAM
    wp_woocommerce_payment_tokens: Data: 0.00MB + Index: 0.00MB + Engine MyISAM
    wp_woocommerce_payment_tokenmeta: Data: 0.00MB + Index: 0.01MB + Engine MyISAM
    wp_woocommerce_log: Data: 0.00MB + Index: 0.00MB + Engine MyISAM
    wp_actionscheduler_actions: Data: 3.02MB + Index: 1.92MB + Engine InnoDB
    wp_actionscheduler_claims: Data: 0.02MB + Index: 0.02MB + Engine InnoDB
    wp_actionscheduler_groups: Data: 0.02MB + Index: 0.02MB + Engine InnoDB
    wp_actionscheduler_logs: Data: 1.52MB + Index: 0.63MB + Engine InnoDB
    wp_adtribes_my_conversions: Data: 0.02MB + Index: 0.02MB + Engine InnoDB
    wp_atum_order_itemmeta: Data: 0.02MB + Index: 0.03MB + Engine InnoDB
    wp_atum_order_items: Data: 0.02MB + Index: 0.02MB + Engine InnoDB
    wp_atum_product_data: Data: 0.02MB + Index: 0.05MB + Engine InnoDB
    wp_berocket_termmeta: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_braapf_product_stock_status_parent: Data: 0.13MB + Index: 0.08MB + Engine InnoDB
    wp_braapf_product_variation_attributes: Data: 0.02MB + Index: 0.05MB + Engine InnoDB
    wp_braapf_term_taxonomy_hierarchical: Data: 0.05MB + Index: 0.05MB + Engine InnoDB
    wp_braapf_variation_attributes: Data: 0.02MB + Index: 0.03MB + Engine InnoDB
    wp_check_email_log: Data: 33.52MB + Index: 0.00MB + Engine InnoDB
    wp_cli_cookie_scan: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_cli_cookie_scan_categories: Data: 0.02MB + Index: 0.02MB + Engine InnoDB
    wp_cli_cookie_scan_cookies: Data: 0.02MB + Index: 0.03MB + Engine InnoDB
    wp_cli_cookie_scan_url: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_cli_scripts: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_cmplz_cookiebanners: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_cmplz_cookies: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_cmplz_services: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_commentmeta: Data: 0.02MB + Index: 0.02MB + Engine MyISAM
    wp_comments: Data: 6.69MB + Index: 3.14MB + Engine MyISAM
    wp_commercekit_searches: Data: 0.14MB + Index: 0.00MB + Engine InnoDB
    wp_commercekit_waitlist: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_commercekit_wishlist: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_commercekit_wishlist_items: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_links: Data: 0.00MB + Index: 0.00MB + Engine MyISAM
    wp_mailchimp_carts: Data: 0.09MB + Index: 0.00MB + Engine InnoDB
    wp_mailchimp_jobs: Data: 0.08MB + Index: 0.00MB + Engine InnoDB
    wp_megamenu_widgets: Data: 0.00MB + Index: 0.00MB + Engine MyISAM
    wp_nm_personalized: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_options: Data: 9.30MB + Index: 1.23MB + Engine InnoDB
    wp_pmxe_exports: Data: 1.31MB + Index: 0.00MB + Engine InnoDB
    wp_pmxe_google_cats: Data: 0.39MB + Index: 0.00MB + Engine InnoDB
    wp_pmxe_posts: Data: 1.52MB + Index: 0.00MB + Engine InnoDB
    wp_pmxe_templates: Data: 0.08MB + Index: 0.00MB + Engine InnoDB
    wp_pmxi_files: Data: 0.01MB + Index: 0.00MB + Engine MyISAM
    wp_pmxi_hash: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_pmxi_history: Data: 0.01MB + Index: 0.00MB + Engine MyISAM
    wp_pmxi_images: Data: 0.20MB + Index: 0.07MB + Engine MyISAM
    wp_pmxi_imports: Data: 1.44MB + Index: 0.00MB + Engine MyISAM
    wp_pmxi_posts: Data: 0.45MB + Index: 0.52MB + Engine MyISAM
    wp_pmxi_templates: Data: 0.00MB + Index: 0.00MB + Engine MyISAM
    wp_postmeta: Data: 56.85MB + Index: 25.22MB + Engine MyISAM
    wp_posts: Data: 6.47MB + Index: 1.72MB + Engine MyISAM
    wp_revslider_css: Data: 0.09MB + Index: 0.00MB + Engine MyISAM
    wp_revslider_layer_animations: Data: 0.00MB + Index: 0.00MB + Engine MyISAM
    wp_revslider_navigations: Data: 0.00MB + Index: 0.00MB + Engine MyISAM
    wp_revslider_sliders: Data: 0.03MB + Index: 0.00MB + Engine MyISAM
    wp_revslider_slides: Data: 0.12MB + Index: 0.00MB + Engine MyISAM
    wp_revslider_static_slides: Data: 0.00MB + Index: 0.00MB + Engine MyISAM
    wp_shipment_batch_process: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_smush_dir_images: Data: 0.25MB + Index: 0.09MB + Engine InnoDB
    wp_stock_log: Data: 0.44MB + Index: 0.00MB + Engine InnoDB
    wp_termmeta: Data: 0.08MB + Index: 0.06MB + Engine MyISAM
    wp_terms: Data: 0.08MB + Index: 0.18MB + Engine MyISAM
    wp_term_relationships: Data: 0.44MB + Index: 0.98MB + Engine MyISAM
    wp_term_taxonomy: Data: 0.10MB + Index: 0.14MB + Engine MyISAM
    wp_usermeta: Data: 0.99MB + Index: 0.54MB + Engine MyISAM
    wp_users: Data: 0.04MB + Index: 0.06MB + Engine MyISAM
    wp_wcfm_daily_analysis: Data: 0.02MB + Index: 0.02MB + Engine InnoDB
    wp_wcfm_detailed_analysis: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wcfm_enquiries: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wcfm_enquiries_meta: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wcfm_enquiries_response: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wcfm_enquiries_response_meta: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wcfm_fbc_chat_rows: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wcfm_fbc_chat_sessions: Data: 0.02MB + Index: 0.02MB + Engine InnoDB
    wp_wcfm_fbc_chat_visitors: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wcfm_fbc_offline_messages: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wcfm_following_followers: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wcfm_messages: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wcfm_messages_modifier: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wcfm_messages_stat: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wcfm_support: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wcfm_support_meta: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wcfm_support_response: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wcfm_support_response_meta: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wcpdf_invoice_number: Data: 0.17MB + Index: 0.00MB + Engine InnoDB
    wp_wc_admin_notes: Data: 0.06MB + Index: 0.00MB + Engine InnoDB
    wp_wc_admin_note_actions: Data: 0.06MB + Index: 0.02MB + Engine InnoDB
    wp_wc_category_lookup: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wc_customer_lookup: Data: 1.52MB + Index: 0.48MB + Engine InnoDB
    wp_wc_download_log: Data: 0.00MB + Index: 0.00MB + Engine MyISAM
    wp_wc_order_coupon_lookup: Data: 0.06MB + Index: 0.06MB + Engine InnoDB
    wp_wc_order_product_lookup: Data: 2.52MB + Index: 2.61MB + Engine InnoDB
    wp_wc_order_stats: Data: 0.50MB + Index: 7.33MB + Engine InnoDB
    wp_wc_order_tax_lookup: Data: 0.02MB + Index: 0.03MB + Engine InnoDB
    wp_wc_product_attributes_lookup: Data: 0.02MB + Index: 0.02MB + Engine InnoDB
    wp_wc_product_download_directories: Data: 0.02MB + Index: 0.02MB + Engine InnoDB
    wp_wc_product_meta_lookup: Data: 0.39MB + Index: 0.64MB + Engine InnoDB
    wp_wc_rate_limits: Data: 0.02MB + Index: 0.02MB + Engine InnoDB
    wp_wc_reserved_stock: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wc_tax_rate_classes: Data: 0.02MB + Index: 0.02MB + Engine InnoDB
    wp_wc_webhooks: Data: 0.00MB + Index: 0.00MB + Engine MyISAM
    wp_woo_shippment_provider: Data: 0.11MB + Index: 0.00MB + Engine InnoDB
    wp_wpgmza: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wpgmza_circles: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wpgmza_maps: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wpgmza_nominatim_geocode_cache: Data: 0.06MB + Index: 0.00MB + Engine InnoDB
    wp_wpgmza_polygon: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wpgmza_polylines: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wpgmza_rectangles: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wpmailsmtp_debug_events: Data: 0.06MB + Index: 0.00MB + Engine InnoDB
    wp_wpmailsmtp_tasks_meta: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wpml_mails: Data: 234.52MB + Index: 0.00MB + Engine InnoDB
    wp_wpmm_subscribers: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wt_iew_action_history: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wt_iew_cron: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wt_iew_ftp: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_wt_iew_mapping_template: Data: 0.02MB + Index: 0.00MB + Engine InnoDB
    wp_yith_wcwl: Data: 0.24MB + Index: 0.13MB + Engine MyISAM
    wp_yith_wcwl_lists: Data: 0.37MB + Index: 0.38MB + Engine MyISAM
    wp_yoast_indexable: Data: 8.52MB + Index: 3.39MB + Engine InnoDB
    wp_yoast_indexable_hierarchy: Data: 1.38MB + Index: 0.55MB + Engine InnoDB
    wp_yoast_migrations: Data: 0.02MB + Index: 0.02MB + Engine InnoDB
    wp_yoast_primary_term: Data: 0.16MB + Index: 0.17MB + Engine InnoDB
    wp_yoast_prominent_words: Data: 0.17MB + Index: 0.19MB + Engine InnoDB
    wp_yoast_seo_links: Data: 0.16MB + Index: 0.11MB + Engine InnoDB
    wp_yoast_seo_meta: Data: 0.22MB + Index: 0.00MB + Engine InnoDB

    ### Post Type Counts ###

    attachment: 4766
    brands: 6
    br_product_filter: 1
    custom_css: 2
    footer: 3
    mc4wp-form: 1
    mts_notification_bar: 4
    nav_menu_item: 249
    oembed_cache: 4
    page: 45
    post: 33
    product: 2915
    product_variation: 13
    revision: 636
    shop_coupon: 13
    shop_order: 6367
    shop_order_refund: 93
    testimonial: 4
    vc_grid_item: 1
    wpcf7_contact_form: 3
    wp_global_styles: 1
    yith_wcan_preset: 2

    ### Security ###

    Secure connection (HTTPS): ?
    Hide errors from visitors: ?

    ### Active Plugins (44) ###

    404 to Homepage: by pipdig – 1.0
    ActiveCampaign: by ActiveCampaign – 8.1.10
    Amount Left for Free Shipping for WooCommerce: by WPFactory – 2.1.9
    Change wp-admin login: by Nuno Morais Sarmento – 1.1.0
    Check & Log Email: by WPChill – 1.0.6
    CommerceGurus Commercekit: by CommerceGurus – 1.3.0
    Contact Form 7: by Takayuki Miyoshi – 5.6.1
    GDPR Cookie Consent: by WebToffee – 2.1.2
    Duplicate Page: by mndpsingh287 – 4.4.9
    Enable Media Replace: by ShortPixel – 3.6.3
    Facebook for WooCommerce: by Facebook – 2.6.19
    Facebook Chat Plugin – Live Chat Plugin for WordPress: by Meta – 2.5
    Flexible Shipping: by Octolize – 4.13.3
    Hotjar: by Hotjar – 1.0.14
    Judge.me Product Reviews for WooCommerce: by Judge.me – 1.3.19
    Kirki Customizer Framework: by David Vongries – 4.0.24
    Mailchimp for WooCommerce: by Mailchimp – 2.7.2
    MC4WP: Mailchimp for WordPress: by ibericode – 4.8.7
    SOGO Add Script Header Footer: by orenhav (SOGO) – 3.9
    Regenerate Thumbnails: by Alex Mills (Viper007Bond) – 3.1.5
    Show Current Template: by JOTAKI Taisuke – 0.4.6
    SVG Support: by Benbodhi – 2.4.2
    Transients Manager: by WPBeginner – 2.0.3
    WooCommerce UPC, EAN, and ISBN: by Scott Bolinger – 0.5.1
    Advanced Shipment Tracking for WooCommerce: by zorem – 3.4.5
    WooCommerce Blocks: by Automattic – 8.2.1
    Product Feed PRO for WooCommerce: by AdTribes.io – 11.7.8
    Payment Plugins for Stripe WooCommerce: by Payment Plugins
    [email protected] – 3.3.25

    Pixel Manager for WooCommerce: by SweetCode – 1.18.1
    WooCommerce Google Analytics Integration: by WooCommerce – 1.5.13
    WooCommerce PayPal Payments: by WooCommerce – 1.9.1 (update to version 1.9.2 is available)
    WooCommerce PDF Invoices & Packing Slips: by WP Overnight – 3.0.1
    PPOM for WooCommerce by N-MEDIA: by Najeeb Ahmad – 30.1
    Stock Manager for WooCommerce: by StoreApps – 2.8.3
    WP All Import – WooCommerce Add-On: by Soflyy – 1.5.1
    WooCommerce: by Automattic – 6.7.0 (update to version 6.8.0 is available)
    Yoast SEO Premium: by Team Yoast – 16.4
    Yoast SEO: by Team Yoast – 19.4
    WP All Export Pro: by Soflyy – 1.6.2
    WP All Import: by Soflyy – 3.6.8
    WP Crontrol: by John Blackbourn & crontributors – 1.14.0
    WP Mail SMTP: by WPForms – 3.5.1
    WP Maintenance Mode & Coming Soon: by Themeisle – 2.4.7
    YITH WooCommerce Gift Cards: by YITH – 2.12.0

    ### Inactive Plugins (0) ###

    ### Must Use Plugins (1) ###

    StackCache: by Stack CP –

    ### Settings ###

    API Enabled: –
    Force SSL: –
    Currency: EUR (€)
    Currency Position: left
    Thousand Separator: ,
    Decimal Separator: .
    Number of Decimals: 2
    Taxonomies: Product Types: external (external)
    gift-card (gift-card)
    grouped (grouped)
    simple (simple)
    variable (variable)

    Taxonomies: Product Visibility: exclude-from-catalog (exclude-from-catalog)
    exclude-from-search (exclude-from-search)
    featured (featured)
    outofstock (outofstock)
    rated-1 (rated-1)
    rated-2 (rated-2)
    rated-3 (rated-3)
    rated-4 (rated-4)
    rated-5 (rated-5)

    Connected to WooCommerce.com: –
    Enforce Approved Product Download Directories: –

    ### WC Pages ###

    Shop base: #52 – /shop/
    Cart: #53 – /cart/
    Checkout: #54 – /checkout/
    My account: #55 – /my-account/
    Terms and conditions: #5394 – /returns-policy/

    ### Theme ###

    Name: Shoptimizer Child Theme
    Version: 1.2.1
    Author URL:
    Child Theme: ?
    Parent Theme Name: Shoptimizer
    Parent Theme Version: 2.4.5
    Parent Theme Author URL: https://www.commercegurus.com/
    WooCommerce Support: ?

    ### Templates ###

    Overrides: shoptimizer-child-theme/woocommerce/emails/customer-processing-order.php

    ### WooCommerce PayPal Payments ###

    Onboarded: ?
    Shop country code: IE
    WooCommerce currency supported: ?
    PayPal card processing available in country: –
    Pay Later messaging available in country: –
    Webhook status: –
    Vault enabled: ?
    Logging enabled: –
    Reference Transactions: –
    Used PayPal Checkout plugin: –

    ### Admin ###

    Enabled Features: activity-panels
    analytics
    coupons
    customer-effort-score-tracks
    experimental-products-task
    experimental-import-products-task
    experimental-fashion-sample-products
    experimental-product-tour
    homescreen
    marketing
    mobile-app-banner
    navigation
    onboarding
    onboarding-tasks
    remote-inbox-notifications
    remote-free-extensions
    payment-gateway-suggestions
    shipping-label-banner
    subscriptions
    store-alerts
    transient-notices
    wc-pay-promotion
    wc-pay-welcome-page
    wc-pay-subscriptions-page

    Disabled Features: minified-js
    settings

    Daily Cron: ? Next scheduled: 2022-08-15 12:57:38 +01:00
    Options: ?
    Notes: 91
    Onboarding: completed

    ### Action Scheduler ###

    Complete: 4,123
    Oldest: 2022-07-15 13:08:11 +0100
    Newest: 2022-08-15 11:15:54 +0100

    Failed: 5
    Oldest: 2019-08-06 14:23:52 +0100
    Newest: 2020-04-03 23:12:11 +0100

    Pending: 5
    Oldest: 2022-08-15 11:37:50 +0100
    Newest: 2022-08-15 18:40:04 +0100

    ### Status report information ###

    Generated at: 2022-08-15 11:16:03 +01:00

Viewing 1 replies (of 1 total)
  • Mirko P.

    (@rainfallnixfig)

    Hi @steadynow,

    Thanks for reaching out!

    There is a checklist on the article below for sites that may be affected by malwares or to enhance better security:

    FAQ My site was hacked

    Please review all the information and hopefully it’ll be helpful for getting the issue resolved. If you still struggle with it after trying all solutions in the article I can recommend asking a site’s security expert for further assistance – https://partners.woocommerce.com/English/marketplace/.

    Let us know if you have any other questions.

Viewing 1 replies (of 1 total)
  • The topic ‘Additional CC fields injected into checkout’ is closed to new replies.