I have the latest version installed and everything is updated, if you access the website from a mobile browser a redirect is made to a spam website.
If I deactivate the theme this does not happen.
You can see it at checkinmag.com. I come with this problem a while ago. I had seen the increase in traffic. I had to block several countries. It seems that they redirect traffic to the website.
Any ideas?
There are instructions on here, somewhere, on how to scrub your database, which you need to do before reinstalling the latest theme *and* the latest td-composer plugin. There was a defect in some code used by *many* themes and plugins in the wild that allowed an injection. However, you need to clean that out of the dbase before anything else.
Once cleaned, consider installing WordFence, at the very least; and do security hardening in htaccess file to disable access to common WP files hackers try to attack. Disable XLMRPC, etc.
See this topic for Newspaper theme — note, this is only for the common wp-zexit hack, not any other issue you have from insecure or nulled third party plugins:
https://forum.tagdiv.com/topic/wp-zexit-malware-and-newspaper-theme-problem-please-see/
(I don’t work here.)
-
This reply was modified 2 years by
simchris.
Hi ignacioribes,
Here are some more recommendations:
Install a plugin for malware and please update the theme to the last version if this is already at the last version, please delete it and replace it with a fresh copy from themeforest account. DO the same for the theme plugins.
If you notice again the site redirects to other sites, it may be because of injected malware. We recommend you follow the steps below:
– Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins;
– Delete the weird/unknown themes;
– Clean unfamiliar Theme Panel injected code (example – https://i.imgur.com/4q70kCv.png);
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)
Thank you!
Thanks simchris and Calin. It seems to be resolved, I removed the wp-zexit plugin and some code that was in the db inside td_live_css_local_storage.
I’ll keep checking just in case.
Thanks again!