Security Problems with WPBakery Visual Composer

Posted in: Newspaper
Post count: 14

Hi,

I have been hacked 2-3 times in the last 2 months and I am using Newspaper Theme + WP Bakery Visual Composer.

Please UPDATE that plugin because I think you have a huge vulnerability there.

Thanks

Post count: 9544

Which version of V.C. are you using?

Have you checked security of your other plugins? Did you update Yoast SEO which had security flaw? Did you update/delete old version of Revolution Slider from early 2014?

Have you renamed your main login from “admin” and deleted that user? … did you change all user passwords to “strong” passwords after intrusion?

are you using “limit login attempts” plugin or similar?

Are you using WordPress 4.2 — 3.9 has security issues. Make sure you have latest version of WordPress.

Have you deleted old plugin folders and old theme folders you’re not using? Old insecure plugins with vulnerabilities can still be executed directly.

Have you tried using something like WordFence if your site is so vulnerable?

Is your server using CSF or other firewall to block port scans and flooding, to totally block bad hat IPs from multiple intrusion attempts?

You need to be aware of ALL such issues, and not just ONE plugin. You can also check the forum for VC on their website(s) for info on the “changelog” for any security issues, and also check SECURI to see if one of your plugins may be vulnerable “right now.”

http://blog.sucuri.net/2015/04

You may want to consider using a security system if you’re unable to lock down your system on your own:

https://wordpress.org/plugins/wordfence/

https://sucuri.net/wordpress-security/wordpress-security-monitoring

Post count: 14

Hey Chris,

I am using 4.4.2 which is the latest version of Visual Composer.

I have checked all the other plugins and they are all updated including SEO by Yoast. I don’t user Revolution Slider.

I have renamed the main user name. I have changed my passwords to strong ones.

I am using WordFence as security plugin.

I am using the latest version of WordPress.

All plugins are correct.

My server is filtering bad IP ranges.

Post count: 9544

4.4.3 does not list any fixes for vulnerabilities and I’ve not seen any industry warnings on vulnerabilities for 4.4.2

https://wpbakery.atlassian.net/wiki/display/VC/Release+Notes

If you believe 4.4.2 is the flaw, you may want to contact the WP Bakery folks — or put in a support ticket with them if you have identified a flaw and WHY you think the plugin is causing your site to be hacked exclusive from other plugins and code you’re using.

Post count: 9544

One assumes you have replaced all your plugins and theme files and reinstalled WordPress to ensure any infected or compromised scripts and exploits have been scrubbed.

Viewing 5 posts - 1 through 5 (of 5 total)
The forum ‘Newspaper’ is closed to new topics and replies.