WPIntell

Source evidence

Plugin used for hacking

Post Layouts for Gutenberg · support · 2023-05-19T11:43:00+00:00

mixedsentiment
highseverity
0.95relevance
7replies
Evidence onlycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

1 / 1 rows with source links

100.0% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

0 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
Kees Lamper resolved
I had an hacked website from a customer where the plugin wasn’t installed. But in FTP there was a plugin folder which has exactly the same name! Same here, 2 sites being installed this plugin, and this plugin wont show on your plugin list until you search the plugin name. Are you guys site added 2 admin user under pif[dot]com as well? Let’s find the common point of this cause, both of my site is using Woodmart theme (themeforest[dot]net/item/woodmart-woocommerce-wordpress-theme/20264492) The theme being mark high risk by patchstack and Malcare. This reply was modified 3 years ago by MK Chan . This reply was modified 3 years ago by MK Chan . This reply was modified 3 years ago by MK Chan . I use the same theme MK Chan! En also have seen the admin users. That’s the issues, need to report this to theme author for sure. I believe a lot more to come. And I found a thread that theme author don’t really treat this seriously. xtemos[dot]com/forums/topic/automatically-update/ I experienced a hack on my site and found this plugin as well (also not in the plugin list, but in my main directory). I also found a plugin (that was in my list), called Hello Press , which looks like a rip-off of the Hello Dolly plugin. I am using the standard WordPress Twentynineteen Theme. Has anyone uncovered any further information? This reply was modified 3 years ago by calliopeconsulting . Interestingly, Post Layouts for Gutenberg will display in your plugin list if you search for it, but it does not show by default: https://www.dropbox.com/s/yx6i144uidp9num/2023-05-20_18-06-44.jpg?dl=0 Today I also found out that the plugin was used for XSS. It has big valnurability issues. Someone must check on that. Hello @ keeslamper , @ MK Chan , @ calliopeconsulting , @ Efs , I have recently updated this plugin to newer version and cross tested the latest version of WordPress and compatibility of PHP version. And resolved some warnings and notices that appear with the debug log. You can feel free to use our plugin with laetst update. Thank you!

Comments

7 shown
MK Chan 2023-05-20T06:08:00+00:00

Same here, 2 sites being installed this plugin, and this plugin wont show on your plugin list until you search the plugin name. Are you guys site added 2 admin user under pif[dot]com as well? Let’s find the common point of this cause, both of my site is using Woodmart theme (themeforest[dot]net/item/woodmart-woocommerce-wordpress-theme/20264492) The theme being mark high risk by patchstack and Malcare. This reply was modified 3 years ago by MK Chan . This reply was modified 3 years ago by MK Chan . This reply was modified 3 years ago by MK Chan .

Kees Lamper 2023-05-20T07:17:00+00:00

I use the same theme MK Chan! En also have seen the admin users.

MK Chan 2023-05-20T08:35:00+00:00

That’s the issues, need to report this to theme author for sure. I believe a lot more to come. And I found a thread that theme author don’t really treat this seriously. xtemos[dot]com/forums/topic/automatically-update/

calliopeconsulting 2023-05-20T21:59:00+00:00

I experienced a hack on my site and found this plugin as well (also not in the plugin list, but in my main directory). I also found a plugin (that was in my list), called Hello Press , which looks like a rip-off of the Hello Dolly plugin. I am using the standard WordPress Twentynineteen Theme. Has anyone uncovered any further information? This reply was modified 3 years ago by calliopeconsulting .

calliopeconsulting 2023-05-20T22:09:00+00:00

Interestingly, Post Layouts for Gutenberg will display in your plugin list if you search for it, but it does not show by default: https://www.dropbox.com/s/yx6i144uidp9num/2023-05-20_18-06-44.jpg?dl=0

Efs 2023-06-06T08:51:00+00:00

Today I also found out that the plugin was used for XSS. It has big valnurability issues. Someone must check on that.

Techeshta 2023-10-25T05:16:00+00:00

Hello @ keeslamper , @ MK Chan , @ calliopeconsulting , @ Efs , I have recently updated this plugin to newer version and cross tested the latest version of WordPress and compatibility of PHP version. And resolved some warnings and notices that appear with the debug log. You can feel free to use our plugin with laetst update. Thank you!