Imunify Detected Malicious Code in Newspaper Theme’s functions.php

Posted in: Newspaper
Post count: 2

Hi team,

Our hosting has scanned our website using Imunify and found the below, which is coming from your theme, Newspaper:
/wp-content/themes/Newspaper/functions.php
SMW-INJ-28647-php.bkdr.obf-0

Do you have any solution for this?
We have verified the original functions.php from your downloaded theme and it’s the same one that is in our hosting so no modifications were done to it.

Post count: 27744

Hello,

I’m sorry to inform you, but this code is not from our theme. What we kindly ask you to do is to download the latest version from ThemeForest, install it, and also verify these steps.
You could consider reinstalling the WordPress version, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins;
– Delete the weird/unknown themes;
– Clean unfamiliar Theme Panel injected code (example – https://i.imgur.com/4q70kCv.png);
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)
Please block /wp-json/tdw/save_css
If an attacker wants to target this URL /wp-json/tdw/save_css they can do so. Even if the website uses a different theme, the attacker can still try that URL. We could add an option to be able to enable/disable the Live CSS, it will be considered. But for now in order to remove it this can only be done with a modification to the composer plugin. I think that all that removing it requires is to comment this line of code – https://prnt.sc/RtwvL5Nc4ikR -> https://prnt.sc/ymZmhdUfp57U But as I mentioned, the attacker can still try to access the URL.

Thank you!

Viewing 2 posts - 1 through 2 (of 2 total)
The forum ‘Newspaper’ is closed to new topics and replies.