Website hacked - phishing

Hi - I was wondering if any of you have any more information about some vulnerabilities the theme had which caused a security breach in one of my websites. The guy behind manage to get in and create some phishing attack to Netflix. The hosting provider showed me the logs and it was referring to this file:

 /wp-content/themes/pro/cornerstone/includes/elements/classic/responsive-text/lkd/CHRILKD/d902c3ce47124c66ce615d5ad9ba304f/signin.php?country=DE-Germany&lang=en 
/wp-content/themes/pro/cornerstone/includes/elements/classic/responsive-text/lkd/CHRILKD/dac32839a9f0baae954b41abee610cc0/signin.php?country=DE-Germany&lang=en
...

Hey Alex,

Downloaded straight from us or from your Apex Dashboard, our Pro theme and Cornerstone plugin does not have additional directories under /pro/cornerstone/includes/elements/classic/responsive-text/. That could have been added there randomly by a malware or the attacker.

We also haven’t received any other report regarding a vulnerability within our products so at this time, this is only unique on your end.

I’d recommend that you hire a website malware cleanup service from a third-party service provider.

Thanks.

My website seems to have been hacked yesterday (6/9/2019) using this ConvertPlus exploit. My hosting company installed a fresh version of Wordpress and I installed the current Pro.zip and Pro-child.zip files without any plugins activated (including default WP plugins). As soon as I activated the child theme, the hack immediately returned. So, yeah, there’s potential for an issue inside the theme itself. Still exploring the exact issue and looking for a solution…

Hi @jeff_cardon,

We’ve updated the ConvertPlus plugin to the 3.4.4 version, it’s is a security update.

Please update your ConvertPlus to this version as well.

If you still need help, I recommend you should contact to Sucuri website:

Regards!

This topic was automatically closed 10 days after the last reply. New replies are no longer allowed.