Ars Technica is reporting thousands of sites have been hacked. After the latest fix. Is there a fix for this???
Hi,
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
I can offer an alternative recommendation if you prefer that we don’t inspect your theme files. You could consider downgrading the WordPress version using the WP Downgrade plugin, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Also, please make sure that you have the latest version 12.6.1
Thank you!
Hi: I have the latest version installed. Are you developing a patch to fix? I’m not infected yest, but it seems only a matter of time. So if there isn’t an imminent fix, it seems prudent to migrate to a new theme. Is your Magazine theme also vulnerable? If not maybe it would be smart to switch?
Hi,
The latest version of the theme is safe -> https://patchstack.com/database/vulnerability/td-composer/wordpress-tagdiv-composer-plugin-4-1-csrf-to-xss-vulnerability. You also need, to check the plugins and wordpress files.
Thank you!