Forum Replies Created

Viewing 2 replies - 1 through 2 (of 2 total)
  • dgruhin

    (@dgruhin)

    I would tend to agree, however if it is core, wouldn’t you think that all the sites on this server would be compromised?

    It is only happening to 1 of them, with an Old version of Avada theme, which has some known security issues per their KB

    prior to version 3.8.3

    https://theme-fusion.com/knowledgebase/avada-3-8-3-xss-security-fix/

    I am updating the theme now to see if it helps this lone site on my server. If not then it is CORE for sure.

    dgruhin

    (@dgruhin)

    I am also experiencing this issue, however only on one of 20+ sites on the same server.

    It is rather annoying, however I have simply made a script for the time being to rename the file back to .php from .php.suspected and stuck it in a cronjob to check every minute.

    I am running Wordfense, IThemes Security, Fail2Ban on the server.

    This site as well as all the others are up to date at 4.2.2 so I am guessing this is due to a plugin.

    Here is my list in an attempt to find some common ground:

    CF7 DatePicker
    Contact Form 7
    Cunjo
    Disable Comments
    Display Posts Shortcode
    Ditty New Ticker
    Ditty RSS Ticker
    Fusion Core
    Google Maps Widget
    iQ Block Country
    iThemes Security
    jCountdown Mega Package for WordPress
    MapPress Easy Google Maps
    Metro Style Social Widget
    Really Simple Captcha
    Responsive Mobile-Friendly Tooltip
    Revolution Slider
    Safe Redirect Manager
    Wordfence Security
    Wordpress SEO by Yoast

    All Plugins are current versions and up to date.

    Theme is Avada version 3.3.1

Viewing 2 replies - 1 through 2 (of 2 total)