Website Compromise and Unauthorized Content Inject

Posted in: Newspaper
Post count: 1

Subject: URGENT: Security Breach on Website Using Newspaper Theme – Russian Betting Spam & Login Issues
Dear tagDiv Support Team,

I am reaching out regarding a critical and ongoing security issue affecting our WordPress website, which uses the Newspaper theme (version 12.7.1) purchased from ThemeForest.

🔐 Problem Description:
Our website — https://nishaanebaz.com/ — is under constant attack, with the following issues occurring:

Unauthorized posting of Russian betting content, likely injected by a bot or script.

Inability to log in to the WordPress admin dashboard, which may indicate privilege escalation or account hijacking.

These incidents have been happening every day since last week, severely affecting site integrity and user trust.

🖥️ Website and Hosting Details:
Website URL: https://nishaanebaz.com/

WordPress Version: 6.8.1

Newspaper Theme Version: 12.7.1

Hosting Provider: Hostinger

First Incident Date: Daily since approximately June 10, 2025

⚙️ Actions We’ve Taken:
Activated maintenance mode to limit further spam posting.

Reset admin password via phpMyAdmin.

Scanned files and database for known malware or spam injection.

Identified and removed unauthorized posts and suspicious users.

🚨 Request for Assistance:
We urgently request your support to:

Investigate any known vulnerabilities or exploitation paths in version 12.7.1 of the Newspaper theme.

Provide guidance, patches, or recommended security settings to harden the theme.

Confirm whether this issue has affected other customers or is specific to our setup.

Share any security best practices or plugin recommendations to prevent recurrence.

As a publicly accessible news platform, this is significantly impacting our publication’s reputation and operation.

We are happy to provide logs, access details, or screenshots upon request. Please treat this as a priority issue.

Post count: 35449

Hello,

If the login area is under attack, it’s most likely due to bots attempting to gain access. I recommend using the Wordfence and Cloudflare security tools.

Wordfence works at the site level to monitor and block suspicious activity.

Cloudflare acts as a protective layer before the traffic even reaches your website, helping to block malicious bots early on.

Both tools can detect attacks and block them either temporarily or permanently. Additionally, they allow you to block specific IP addresses, regions, or even entire countries, depending on your needs.

Thank you!

Post count: 9544
Viewing 3 posts - 1 through 3 (of 3 total)
You must be logged in to reply to this topic.