Passer la navigation

[Résolu] Wordfence flagging toolset blocks as having malicious code

This support ticket is created Il y a 2 weeks, 4 days. There's a good chance that you are reading advice that it now obsolete.

This is the technical support forum for Toolset - a suite of plugins for developing WordPress sites without writing PHP.

Everyone can read this forum, but only Toolset clients can post in it. Toolset support works 6 days per week, 19 hours per day.

Sun Mon Tue Wed Thu Fri Sat
- 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 -
- 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 -

Fuseau horaire du supporter : Asia/Kolkata (GMT+05:30)

Ce sujet contient 1 reply, a 1 voix.

Dernière mise à jour par scottL-3 Il y a 2 weeks, 3 days.

Assisté par: Minesh.

Auteur
Publications
#2873035

Wordfence is reporting this on multiple sites:

Critical Problems:
* File appears to be malicious or unsafe: wp-content/plugins/toolset-blocks/vendor/toolset/common-es/public/toolset-common-es-frontend.js

#2873077

Minesh
Supporter

Les langues: Anglais (English )

Fuseau horaire: Asia/Kolkata (GMT+05:30)

Hello. Thank you for contacting the Toolset support.

When using optimization plugins, we already mentioned to exclude that file:
- https://toolset.com/faq/how-to-use-optimization-plugins-with-toolset/#toolset-resource-files

Can you please share a zip of the "toolset-blocks" plugin that contains the file you mentioned and our Devs will check further. You can upload the zip with any file sharing service and send me link to download it.

#2873122

You can close this ticket. The malicious code seems to have come in through a non-Toolset vulnerability and affected a couple js files in different plugins including Toolset Blocks and Views.