hi,
from past couple of days, someone continuously hitting wp-json/tdw/save_css on my blog. It looks like some kind of theme vulnerability that hackers are trying to exploit. Can you please urgently help how to stop hackers from accessing this? or what should be the next action?
Hello,
Please let me know what version of the theme you have.
Please make sure that you have the latest version of the theme 12.6.4
If an attacker wants to target this URL /wp-json/tdw/save_css they can do so. Even if the website uses a different theme, the attacker can still try that URL. We could add an option to be able to enable/disable the Live CSS, it will be considered. But for now in order to remove it this can only be done with a modification to the composer plugin. I think that all that removing it requires is to comment this line of code – https://prnt.sc/RtwvL5Nc4ikR -> https://prnt.sc/ymZmhdUfp57U But as I mentioned, the attacker can still try to access the URL.
Thank you!
Hi there,
Thanks for the update. Yes i have the latest theme version (Newspaper Version: 12.6.4). Also i have disabled the live css by commenting the highlighted code.
Blocking Ip is also not working surprisingly for those IPs where he is hitting that service and I am checking that part with my hosting provider.
But since hacker is still hitting that page, can he do some damage to the site or sniff on any critical information like credentials etc?
Hi,
Have you tried blocking them with wordfence? Something like this would work – https://prnt.sc/1V-dHi7xTQXk But it may take some time until all the URLs are blocked, as they keep changing most likely. Eventually they will all be blocked however and the attack will stop.
I think it could be done from cloudflare as well, if you use cloudflare. That URL can be blocked like this for example – https://community.cloudflare.com/t/possible-to-block-specific-page-access/106765/3 In case you are using cloudflare, this would be a very good solution because cloudflare will block them before they reach the website. But in case it isn’t possible to set up cloudflare, the wordfence method will work as well. Please try it as soon as possible.
Thank you!
Thanks for the update. I have been doing changes and checking the hits but unfortunately I am still getting the hits even though i blocked the URI (/wp-json/tdw/save_css
) from cloudflare as per the screenshot. I even tried different variation(like URI, URI path, full URI etc) to make sure i am not making any mistake but it did not help.
Also my hosting provider is still not able to figure it out why hackers IPs are not getting blocked. Surprisingly when I block my own IP, it works so its very strange.
I also made couple of more changes as per below blog post suggestion:
hi there,
Not sure what files to clean. My site was fine until couple of hours ago but it suddenly screwed as everything disappeared. Probably hackers did something? Below is the URL. Can you please urgently take a look and advise as its down?
Now i clear the cache as homepage was screwed and its up now. Can you please take a look and advise if anything should be done urgently?
Hi,
Please get in touch with us via email at contact@tagdiv.com and provide the wp-admin and cPanel access.
Thank you!
Hi,
I managed to block this page from Cloudflare. Some of the IPs are getting blocked which are trying to access this page. Surprisingly, few of them are passing for the same URI as I can see the hits.
https://hikinginsights.com/wp-json/tdw/save_css
80.82.78.133
/wp-json/tdw/save_css
2/20/24, 11:59 AM
226