Newspaper Theme Keeps Getting Hacked

Posted in: Newspaper
Post count: 12

We are having an issue where the Newspaper theme keeps getting hacked and the hacker is inserting code in the “Your Header Ad” section so that popups occur.

  • This topic was modified 9 years by 84KcZ.
Post count: 9544

Theme not getting hacked, YOUR site is getting hacked.

a) see my tutorial in the forum on hardening your site
b) scan site with Securi once a week
c) make sure WordPress updated since all versions prior to 4.7 are insecure
d) make sure you read the tutorial on WordPress.org on how to ‘harden’ your site for better security

( I don’t work here, but manage dozens of sites for 20+ years. )

Post count: 12

We do use Securi and keep WordPress constantly updated. We have an https site, with numerous malware trackers. We host several sites with the company, and it’s only happening with our two sites using the Newspaper theme.

Post count: 9544

Well, none of our sites have been hacked using the theme. So, obviously if the theme is secure, it means something in your site/server setup is not.

Sorry for the feedback. Good luck!

Post count: 21

Same thing is happening with my website. I was using previous version of Newspaper (around 1 year old version)

Can anyone tell me if newer version is fine and will not get any Malware?

Someone was injecting this script in header traffictrade.life/scripts.js

Can anyone confirm if this was because of using old version of newspaper theme? New version is secured ?

Post count: 42

thew malware is in the database files
It happened to some sites I was managing,

1) run a mysql search for : %%traffictrade%%
2) delete it from table
3) switch to latest php version
4) make sure to change all passwords

I would also check on some of the plug ins that have been installed

like Chris posted above scan your site with scuri make sure none of your photos, plugins are clean

Post count: 12

Another good discussion on this topic, including a lengthy warning from WP Engine Hosting, is including in the thread titled Security Risk.

One user of the Newspaper theme received the following message:

At WP Engine we take security very seriously and make every effort to keep our customers aware of any potential issues. We are reaching out to you today because we identified your site(s) are utilizing the “Newspaper” premium theme.

We have been notified by Sucuri about a recent increase in exploits that specifically target outdated versions of this theme. They operate by injecting unwanted ads into the page’s links, directing visitors away from the intended site. You can read more about the specifics of the exploit here:

https://blog.sucuri.net/2017/06/unwanted-shorte-st-ads-in-unpatched-newspaper-theme.html

Due to the potential severity of this exploit, we strongly recommend that everyone using a version older than 6.7.2 update to the latest version. You can update this through the wp-admin dashboard, but if you have a customized version of the theme, you may want to consult with your developer to ensure your site does not encounter issues when updating. Please make sure to run a backup of your database first; which you can learn how to do here in an article: http://wpengine.com/support/restore/ or here in an interactive walkthrough: https://my.wpengine.com/dashboard/?walkthrough_id=2278

If your site does appear to be displaying the symptoms, the fix is quite easy to remove the exploited code. You will need to remove that code from the Newspaper theme panel’s “header ad” block in WordPress admin interface under Newspaper > Theme panel > ADS > YOUR HEADER AD. You can also replace it with your original ad code, and your site should return to normal. Be sure to update the theme in conjunction with making this change, as it will prevent any further compromises.

Post count: 9544

Also good to setup a security policy internally — you should be checking update changelog/readmes for *all* plugins/themes you use and for WordPress core — as the TagDiv theme security notice for 6.7x was included way back in April 2016:

Version 6.7.2 – April 27th, 2016
fix: social counter facebook issue with new API keys
fix: security issue

a minor issue with 7.0 was fixed with 7.1 for those early adopters who rushed to install 7.0

Version 7.1 – May 20th, 2016
fix: panel got stuck while saving in specific cases, mostly related to categories
fix: Related articles filter was not working with the settings from the panel if you choose related by tags and the post had no tags set.
fix: contributor users cannot change the post template now, this is more in line with WordPress
fix: Security issues
fix: back to top on ie9
fix: missing woocommerce add to cart on mobiles

==============
Everything on the web requires periodic checkups; it’s not static like old websites with static shtml files or similar. WordPress, plugins, PHP, MySQL, WooCommerce, etc., all need to be *checked* when updates are done — new features, no need to upgrade unless you read the help info first; for security patches, these should *always* be done when originally notified!

I don’t work here — but our ‘security practice policy’ internally forces us to CHECK when new updates come out to see WHY they were updated, in case of security issue(s).

Recommended you consider the same, or higher a company to do it for you.

Viewing 8 posts - 1 through 8 (of 8 total)
The forum ‘Newspaper’ is closed to new topics and replies.