Saltar navegación

[Resuelto] Wordfence flagging toolset blocks as having malicious code

This is the technical support forum for Toolset - a suite of plugins for developing WordPress sites without writing PHP.

Everyone can read this forum, but only Toolset clients can post in it. Toolset support works 6 days per week, 19 hours per day.

Sun Mon Tue Wed Thu Fri Sat
- 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 -
- 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 -

Zona horaria del colaborador: Asia/Kolkata (GMT+05:30)

Este tema contiene 1 respuesta, tiene 1 mensaje.

Última actualización por scottL-3 2 weeks, 3 days ago.

Asistido por: Minesh.

Autor
Mensajes
#2873035

Wordfence is reporting this on multiple sites:

Critical Problems:
* File appears to be malicious or unsafe: wp-content/plugins/toolset-blocks/vendor/toolset/common-es/public/toolset-common-es-frontend.js

#2873077

Minesh
Colaborador

Idiomas: Inglés (English )

Zona horaria: Asia/Kolkata (GMT+05:30)

Hello. Thank you for contacting the Toolset support.

When using optimization plugins, we already mentioned to exclude that file:
- https://toolset.com/faq/how-to-use-optimization-plugins-with-toolset/#toolset-resource-files

Can you please share a zip of the "toolset-blocks" plugin that contains the file you mentioned and our Devs will check further. You can upload the zip with any file sharing service and send me link to download it.

#2873122

You can close this ticket. The malicious code seems to have come in through a non-Toolset vulnerability and affected a couple js files in different plugins including Toolset Blocks and Views.