• This plugin keeps appearing in my installation as a virus, they are injecting it in some way to mask the invasion and add a backdor.

Viewing 6 replies - 1 through 6 (of 6 total)
  • Same for me. Did you find an solution @ofmarconi ?

    Yes my Site got hacked as well. The Three Column Screen Layout plugin by Chad appeared 4 times and my site was getting redirected.

    I got hit as well. Cleaned it off but it reappeared a few days later. I’m on Inmotion hosting.

    • This reply was modified 5 years, 5 months ago by Brian Shim.

    My plugins at the time of hack:
    – Admin Columns
    – Advanced Custom Fields
    – Classic Editor
    – Custom Post Type UI
    – Divi Accessibility
    – Duplicator
    – Imsanity
    – Post Types Order
    – Really Simple SSL
    – Spotlight – Social Media Feeds
    – Wordfence
    – Yoast SEO

    A client of mine has the same issue. I did a scan with WordFenc and Sucuri and both didn’t find anything.

    The only plugins in common with Brian are WordFence and Yoast.

    Other than that the plugins installed are:

    Antispam Bee
    Avada Builder
    Avada Core
    BackupBuddy
    Contact Form 7
    Events Shortcodes and Templates Addon
    Green Popups (formerly Layerd Popups)
    Mailster – Email Newsletter Plugin for WordPress
    ManageWP – Worker
    Paytium
    The Events Calendar
    Ultimate GDPR & CCPA
    WordFence Security
    WP Reset Pro
    Yoast SEO

    Did anyone solve this or found the culprit?

    When setting up Wordfence check it to scan outside of the WordPress directories in case it finds anything there.

Viewing 6 replies - 1 through 6 (of 6 total)

The topic ‘Virus’ is closed to new replies.