Security Issues

Posted in: Newsmag
Post count: 207

Hello,

For my pavlikeni.com, some of the links of the stories I publish (you can test with the links of the big images on top) are hijacked and lead to external sites. The WP version of your software is up-to-date, but seems to have been infected. Please address this issue urgently.

Thanks,
Peter

Post count: 6535

Hi

We have tested the theme security rigorously before releasing and also it was tested and analyzed by Envato reviewers and if would have any security issues would not pass their reviews.
Also I’ve test your site with a malware security scanner and fond some malicious activities: https://sitecheck.sucuri.net/results/pavlikeni.com/http://screencast.com/t/ktyzW0bxVB Checking our demo too can be seen that is no thread there so can’t be a theme’s issue: http://screencast.com/t/hfBXLFGJSqzD
Try to deactivate all plugins except Visual Composer, clear all caches and test again. Also I found here some resources that may help you fixing this iisues: http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/http://vivavivugeek.blogspot.ro/2014/03/detect-and-remove-spam-seo-blackhat-seo.html

Hope this help.
Thanks!

Post count: 207

Hello,

Thanks for the response, but saying that your demo is not infected yet does not mean it cannot be infected. I have done nothing but automatically update to your latest version and WP got in this state.

Please advise.

Thanks,
Peter

Post count: 9544

Theme has no infections. We’ve been using it for 2 years on multiple sites and we check system consistently for any issues including Google search console, dedicated server scanning, Securi, PCI-DSS etc.

You need to have your site checked carefully for malware, change passwords, reinstall all plugins from clean copies; remove any old themes and plugins not in use; scan your site with SECURI (free), and if your host has a security scanning service have them also check for rootkits and other nonsense.

Only YOU can fix your site if its been compromised. Note that some older versions of plugins, WordPress itself, are hackable, so these need to be up to date. Many older plugins prior to 2015 and not updated may have the cross-site vulnerability, comment injection vulnerabilities, etc.

Post count: 207

Hi,

Thanks for your respnse. I updated the script to the latest one you provided a few days ago and this is when the issue presented itself.

I am not a programmer and cannot fix the site the way you suggest. I am sure I am not the only person affected now or in the future.

Please advise who could help for a one-time fee, because, again, I am not a programmer and cannot fix.

Thanks,
Peter

Post count: 9544

Best first steps:
Change your theme being used to default WP theme (eg twenty-fifteen)

a) remove/delete all themes except for the 3 default themes with WordPress
b) remove/delete all plugins you’re not using (e.g., old ones from old themes, anything new you’ve installed recently not included with the theme)
c) change *all* your passwords for WordPress, and your hosting account ASAP.
d) reinstall ALL your plugins (delete old ones entirely, replace with new ones via FTP), and download new copy of the theme from ThemeForest — delete old Newsmag folder, upload NEW copy — don’t over-write ANY old folders during this process

dd) install full clean copy of WordPress — do this by FTP; delete the wp-includes and wp-admin folders, upoload new ones from fresh download of WP from WordPress.org; over write the files in root (be sure to backup your wp-config.php and .htaccess files)

ddd) double check your htaccess file for any weirdness such as redirects to other websites

e) rescan your site with SECURI scanner.

If your content has been infected at the post level, you may need to manually edit each post to remove “injected” content.

Once your site is “fixed” — consider reading up on numerous security posts online to do stuff like
a) delete admin account as super user
b) install tools like “limit login attempts”
c) consider disabling comments and pingbacks entirely unless you have need for them; consider using plugin like Disqus instead
d) read up on any plugin on wordpress.org before install; don’t install oddball plugins “free on the web someplace”
e) make regular backups of theme settings, wp settings export, php dbase clone and save, etc., full ftp download of all assets to local drive

Hopefully that all may give you some guidance and perhaps starting point on some things you can do yourself before finding somebody to hire.

Viewing 6 posts - 1 through 6 (of 6 total)
You must be logged in to reply to this topic.