Another good discussion on this topic, including a lengthy warning from WP Engine Hosting, is including in the thread titled Security Risk.
One user of the Newspaper theme received the following message:
At WP Engine we take security very seriously and make every effort to keep our customers aware of any potential issues. We are reaching out to you today because we identified your site(s) are utilizing the “Newspaper” premium theme.
We have been notified by Sucuri about a recent increase in exploits that specifically target outdated versions of this theme. They operate by injecting unwanted ads into the page’s links, directing visitors away from the intended site. You can read more about the specifics of the exploit here:
https://blog.sucuri.net/2017/06/unwanted-shorte-st-ads-in-unpatched-newspaper-theme.html
Due to the potential severity of this exploit, we strongly recommend that everyone using a version older than 6.7.2 update to the latest version. You can update this through the wp-admin dashboard, but if you have a customized version of the theme, you may want to consult with your developer to ensure your site does not encounter issues when updating. Please make sure to run a backup of your database first; which you can learn how to do here in an article: http://wpengine.com/support/restore/ or here in an interactive walkthrough: https://my.wpengine.com/dashboard/?walkthrough_id=2278
If your site does appear to be displaying the symptoms, the fix is quite easy to remove the exploited code. You will need to remove that code from the Newspaper theme panel’s “header ad” block in WordPress admin interface under Newspaper > Theme panel > ADS > YOUR HEADER AD. You can also replace it with your original ad code, and your site should return to normal. Be sure to update the theme in conjunction with making this change, as it will prevent any further compromises.
I should have mentioned. You need to go to Theme Panel, then Ads, then Header Ad. There will be a section called Your Header Ad. The hacker will have installed the code in this box. You delete the code, and the problem with stop. However, the code will eventually reappear, and then you have to remove it again.
This is very interesting information. This is exactly the issue I’ve been having with the Newspaper theme. Not happening on any of my other themes. I have version 6.7 on two different sites that continue to get hit. I actually sent a support ticket today about it, but have not heard back from the Newspaper support group. As you can see by the numerous support tickets in recent days, it’s not easy to upgrade to version 8 because of recent conflicts between Newspaper and Visual Composer. Newspaper wants you to start using TagDiv instead, but this forces you to rebuild all your pages.
We do use Securi and keep WordPress constantly updated. We have an https site, with numerous malware trackers. We host several sites with the company, and it’s only happening with our two sites using the Newspaper theme.
Hi all,
We tried several browser (and cleared them). The server is not running pagespeed, atm, it is running zend opcache but I have just restarted PHP so that would clear out. Nothing the replacement thumbnails are not there. So I guess my question is where should I drop in a default thumbnail for anything that has no thumbnail
George
Hi B,
No dice it’s not there which is strange. Would there be any other reason for this issue.
George