Search (advanced search) | ||||
Use this Search form before posting, asking or make a new thread.
|
12-03-2014, 03:39 AM
(This post was last modified: 12-03-2014 06:57 AM by me-alain.)
Post: #1
|
|||
|
|||
WARNING !! ABOUT THEMEFOREST ROYAL THEME...
An M**** because I call'd it a M**** and the term is still weak, slipping malicious code in the theme files.
It is also add the domain name directly into some images of theme options. This M**** , that big M**** , it is called wplocker.com. An example : If you change Royal theme options in the options of the theme and click on save changes, a black image appears referring to domain wplocker.com To remove this malicious code, go to the theme folder : option-tree/includes/ot-ui-theme-options.php - and at line 39, delete the following codes : Code: <br><img src="http://www.ten28.com/yt.jpg"> Code: http://www53.zippyshare.com/v/90877457/file.html **************** New find : In folder framework/theme-options.php - line 2072 delete codes : Code: <br><img src="http://www.lolinez.com/sg.jpg"> |
|||
12-03-2014, 09:18 AM
Post: #2
|
|||
|
|||
RE:
Thanks
Please keep us informed like this |
|||
12-03-2014, 12:57 PM
Post: #3
|
|||
|
|||
RE:
Quite usual with wplocker. Been years since they started doing it over there.
|
|||
06-26-2015, 11:31 AM
(This post was last modified: 06-26-2015 11:43 AM by DaniloIN.)
Post: #4
|
|||
|
|||
RE: WARNING !! ABOUT THEMEFOREST ROYAL THEME...
New backdoor from wplocker.com at latest theme-update 2.0
<img src="http://www.ten28.com/qa.jpg"> /framework/theme-functions.php base64 - PGltZyBzcmM9Imh0dHA6Ly93d3cudGVuMjguY29tL3FhLmpwZyI+ |
|||
06-26-2015, 02:40 PM
Post: #5
|
|||
|
|||
RE: WARNING !! ABOUT THEMEFOREST ROYAL THEME... | |||