Theme activation error - report of vulnerable script from host company

Hey there,

we’re just setting up a new site and have had a problem with activation of the theme.

please see below from what we received from the web host.

+++++++++++++++++++++

Hello,

Thank you for your patience. I can see that ‘/home/dbartatt/public_html/wp-content/themes/pro/cornerstone/includes/classes/styling/class-font-manager.php’ file permission was changed to 000 and that was causing the issue. Upon further checking, I can see that above-mentioned file was defaced/injected with the vulnerable script. So kindly upload mentioned file to the server to correct the issue.

root@wp1 [/home/dbartatt/public_html/wp-content/themes/pro/cornerstone/includes/classes/styling]# ls -ld class-font-manager.php
---------- 1 dbartatt dbartatt 7463 Aug 8 22:41 class-font-manager.php
root@wp1 [/home/dbartatt/public_html/wp-content/themes/pro/cornerstone/includes/classes/styling]#

Let us know if you have any questions.

++++++++++++++++++++++++++++++

ENB…// ( on behalf of DBarTattoos)

Hey there,

i just received, this from the host to clarify.

++++++++++++++++++

Hello,

Thank you for contacting us. Please check with the theme developing team that the following code is secure?

“/home/dbartatt/public_html/wp-content/themes/pro/cornerstone/includes/classes/styling/class-font-manager.php”, line number 213.

++++++++++++++++++++

ENB…// ( on behalf of DBarTattoos)

Hey there,

The file is secure. Your WordPress files and folders permission might be insecure so humans or bots have easy access to edit your files. Please see http://www.wpbeginner.com/beginners-guide/how-to-fix-file-and-folder-permissions-error-in-wordpress/ regarding WordPress files and folder permissions. You also need to secure other areas of WordPress. See https://codex.wordpress.org/Hardening_WordPress

Thanks.