Jump to content

Archived

This topic is now archived and is closed to further replies.

Simon

Themes Requiring Updates

Recommended Posts

Simon
Please Note: Recent software such as DMS is not affected by this security advisory.
 

Three days ago we were alerted by Securi via email that there were a couple of problems with two of our legacy themes, namely PlatformPro and PageLines Framework.

 

We take security seriously, so we wasted no time updating the free versions of these themes on the WordPress Repo and updating the pro versions over here at pagelines.com

 

The following versions of the two themes have been patched and are available from your account area right now.

 

PlatformPro 1.6.2 [download]
PageLines Framework 2.4.6 [download]

 

If you are using the free versions of the two themes available on wordpress.org, those files have also been patched.

 

PageLines 1.4.6 [download]
Platform 1.4.4 [download]

 

In all cases you should see an update available in your WordPress admin area and should update right away.

In the event that you cannot update the theme we took the time to create a small plugin that will protect your site.

The plugin will work with all versions of both themes, just install and activate it for immediate protection.

 pl-security-patcher.zip

 

 

Share this post


Link to post
Share on other sites
trisquelmedia

Thxs a lot for support!! updating..

Share this post


Link to post
Share on other sites
lakersalex

I can't download the plugin pl-security-patcher.zip

 

Sorry, you don't have permission for that!
 
You do not have permission to view this attachment.
 
Can you provide a link to the plugin?

Share this post


Link to post
Share on other sites
bartoncollege

I'm running Platform Base 1.41 with Platform Pro 1.5.3.  Does the plugin cover those versions?  I apply the plugin and activate it, but the site gets hacked again after several hours.

Share this post


Link to post
Share on other sites
Simon

The plugin works for any version of platformpro. If your site has already been hacked, if they even used platformpro as a way in, installing a plugin wont 'lock them out' as they have already compromised the server.

How do you know you have been hacked?

Share this post


Link to post
Share on other sites
bartoncollege

Our page elements (boxes, features, etc.) were jumbled, and our list of majors was showings links to buy various pharmaceuticals.  Things seems to be okay now.  I completely deleted the contents of the root directory and restored from a backup that was a day older than what I thought was the last safe backup. Immediately, added the plugin again and also added the Sucuri Security plugin.  I think the Pagelines plugin is most likely fine.  I think using a too recent backup was probably the reason why it kept coming back.  I just wanted to check with you guys to be sure that my version was covered.

 

I've been playing with DMS 2 on a test server, so this incident will just speed the transition up. :-)

 

Thanks for answering my question and thanks for the plugin.

Share this post


Link to post
Share on other sites
bonnysteele

I'm using Framework and pretty sure our site has been and still is hacked. I'm seeing all sorts of movie downloads in my link directory (image linked below) and some users have reported a malicious pop up suggesting a flash update. Others seeing this and possible suggestions? 

 

http://ewiconnect.com/images/Screen%20Shot%202015-02-05%20at%204.23.16%20PM.png

 

I just activated the patch plugin and I am running the latest version of Pagelines Framework. Help?

Share this post


Link to post
Share on other sites
Simon

Installing the patch and updating the theme after you have been hacked isnt going to magically fix it im afraid.

 

http://codex.wordpress.org/FAQ_My_site_was_hacked

 

You will need to clean the site.

 

If you have a list of URLS being added to the site then search for those urls in the database.

 

Check all user accounts, remove any other admins, change your passwords.

Share this post


Link to post
Share on other sites
bonnysteele

Thanks for the guidance. I found a test user account that was the source. Removed the account and all associated posts (there were 50+) and that seems to have taken care of it. All other passwords changed.

 

Gracias.

Share this post


Link to post
Share on other sites

  • Similar Content

    • PeriniNero
      By PeriniNero+
      After update this message appears from Vaultpress. Any idea how to fix? Or just ingore? :-)
      "PHP. Suspicious.Eval.1"
      in .../themes/dms/dms/includes
      1061
      Thank you.
       
       
    • satronen
      By satronen
      I am currently using Pagelines Framework 2.4.6
      I'm interested to upgrade my site to iBlogPro6
      Will I be able to keep my Pagelines Framework website live and uninterrupted while building my new iBlogPro6 site?
      Is there a online help guide of specifics instructions how to get this process started once I download iBlogPro6?
    • satronen
      By satronen
      I am currently using Pagelines Framework 2.4.6
      I'm interested to upgrade my site to iBlogPro6
      Will I be able to keep my Pagelines Framework website live and uninterrupted while building my new iBlogPro6 site?
      Is there a online help guide of specifics instructions how to get this process started once I download iBlogPro6?
    • flaxpits
      By flaxpits
      Is there a way to use the whole image in the feature slider as a link? I have searched the forum and noticed in 2011 this was posted and the reply was no. Has anything changed in 4 years?
       
    • aldisney
      By aldisney+
      Hello--
      I haven't seen this come up on the forums, but since Chrome's required for PageLines, I thought it might be helpful to share this information with the community - I've been tearing my hair out about this all week.
      Chrome's most recent update, to use non-technical terminology, broke the crap out of a ton of Wordpress sites and other web applications. Chrome's forcing sites to look for HTTPS when there's no HTTPS to be found, which, in some cases, prevents you from accessing your Wordpress site entirely. Here's a pretty good explanation of what's going on: https://ma.ttias.be/chrome-44-sending-https-header-by-mistake-breaking-web-applications-everywhere/
      Per the article and Google's release schedule, it looks like the issue's supposed to be fixed in the next update, Monday, 27th of 2015. For our customers, we're going to ride it out and see if a fix gets implemented on schedule, but the article comments include a plugin hosted on Github that resolves the issue.
      In any case, if there's anyone else going crazy trying to figure out what's going on with their sites, I hope this helps. 
×