Title: Malware Found
Last modified: September 3, 2016

---

# Malware Found

 *  [saniul_12](https://wordpress.org/support/users/saniul_12/)
 * (@saniul_12)
 * [11 years, 4 months ago](https://wordpress.org/support/topic/malware-found-2/)
 * i think we should stop using this plugin. Behind the reason lies. The better 
   is to remove this plugin from the repository.
 * [code]
    [http://blog.sucuri.net/2015/02/zero-day-in-the-fancybox-for-wordpress-plugin.html](http://blog.sucuri.net/2015/02/zero-day-in-the-fancybox-for-wordpress-plugin.html)[/
   code]

Viewing 4 replies - 1 through 4 (of 4 total)

 *  [Jose Pardilla](https://wordpress.org/support/users/moskis/)
 * (@moskis)
 * [11 years, 4 months ago](https://wordpress.org/support/topic/malware-found-2/#post-7928615)
 * Hi saniul_12,
 * Feel free to stop using the plugin but please note that the vulnerability was
   fixed with version 3.0.3 the day it was found.
 * More info: [https://wordpress.org/plugins/fancybox-for-wordpress/faq/](https://wordpress.org/plugins/fancybox-for-wordpress/faq/)
 *  [fabianrios](https://wordpress.org/support/users/fabianrios/)
 * (@fabianrios)
 * [11 years, 3 months ago](https://wordpress.org/support/topic/malware-found-2/#post-7928638)
 * Jose but you should make a comment in the plugin or manage a way of telling people
   to update the plugin because you found a vulnerability, it took me a while before
   I found where the malware was.
 *  Thread Starter [saniul_12](https://wordpress.org/support/users/saniul_12/)
 * (@saniul_12)
 * [11 years, 3 months ago](https://wordpress.org/support/topic/malware-found-2/#post-7928639)
 * thanks.
 *  [javierfaus](https://wordpress.org/support/users/javierfaus/)
 * (@javierfaus)
 * [11 years, 1 month ago](https://wordpress.org/support/topic/malware-found-2/#post-7928644)
 * Just tested version 3.0.6 and the malware is still there…
 * ////
 * As soon as I installed the plugin my Sucuri Security Scan alerts me:
 * [http://labs.sucuri.net/db/malware/malware-entry-mwjsgen2?web.js.malware.fancybox.001](http://labs.sucuri.net/db/malware/malware-entry-mwjsgen2?web.js.malware.fancybox.001)
 * I have been also contacted from a few people telling me that my website was redirecting
   them to other SPAM pages.
 * Please make sure before installing that this issue has been cleared.
 * Cheers.
    Javier Faus.

Viewing 4 replies - 1 through 4 (of 4 total)

The topic ‘Malware Found’ is closed to new replies.

 * ![](https://ps.w.org/fancybox-for-wordpress/assets/icon-256x256.jpg?rev=1864321)
 * [FancyBox for WordPress](https://wordpress.org/plugins/fancybox-for-wordpress/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/fancybox-for-wordpress/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/fancybox-for-wordpress/)
 * [Active Topics](https://wordpress.org/support/plugin/fancybox-for-wordpress/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/fancybox-for-wordpress/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/fancybox-for-wordpress/reviews/)

 * 4 replies
 * 4 participants
 * Last reply from: [javierfaus](https://wordpress.org/support/users/javierfaus/)
 * Last activity: [11 years, 1 month ago](https://wordpress.org/support/topic/malware-found-2/#post-7928644)