Suspicious Code in plugin files
-
I use Wordfence security software to scan my site. Two MailPoet files showed in today’s scan.
My MailPoet is Version 2.6.19.
Are these filenames valid for the plugin?
Are the data valid that are shown In the details provided below?Details follow.
Summary of suspicious files:
* File contains suspected malware URL: /home/hcwg/public_html/dev/wp-content/plugins/wysija-newsletters/helpers/back.php
* File contains suspected malware URL: /home/hcwg/public_html/dev/wp-content/plugins/wysija-newsletters/add-ons/add-ons-list.phpDetails for each follow:
********* first file *********
/home/hcwg/public_html/dev/wp-content/plugins/wysija-newsletters/helpers/back.php
Filename: dev/wp-content/plugins/wysija-newsletters/helpers/back.php
Bad URL: https://clicky.me/wp-reviews
File type: Not a core, theme or plugin file.
Issue first detected: 1 hour 30 mins ago.
Severity: Critical
Status New
This file contains a suspected malware URL listed on Google’s list of malware sites. Wordfence decodes base64 when scanning files so the URL may not be visible if you view this file. The URL is: https://clicky.me/wp-reviews – More info available at Google Safe Browsing diagnostic page.********* end first file *****
********* second file *********
/home/hcwg/public_html/dev/wp-content/plugins/wysija-newsletters/add-ons/add-ons-list.php
Filename: dev/wp-content/plugins/wysija-newsletters/add-ons/add-ons-list.php
Bad URL: https://clicky.me/woocommerce-autoresponder
File type: Not a core, theme or plugin file.
Issue first detected: 1 hour 30 mins ago.
Severity: Critical
Status New
This file contains a suspected malware URL listed on Google’s list of malware sites. Wordfence decodes base64 when scanning files so the URL may not be visible if you view this file. The URL is: https://clicky.me/woocommerce-autoresponder – More info available at Google Safe Browsing diagnostic page.
********* end second file *****
- The topic ‘Suspicious Code in plugin files’ is closed to new replies.