• Hello. I have received the following messages in my wordfence admin:

    Modified plugin file: wp-content/plugins/calculated-fields-form/js/fields-public/04_fbuilder.fdate.js
    Filename:wp-content/plugins/calculated-fields-form/js/fields-public/04_fbuilder.fdate.js
    File type:Plugin
    Issue first detected:12 hours 45 mins ago.
    Severity:Warning
    StatusNew
    :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
    Modified plugin file: wp-content/plugins/calculated-fields-form/css/stylepublic.css
    Filename:wp-content/plugins/calculated-fields-form/css/stylepublic.css
    File type:Plugin
    Issue first detected:12 hours 45 mins ago.
    Severity:Warning
    Status New

    BUT I DIDN´T EDIT THE PLUGIN CODE AND NEITHER UPDATED IT. IT’S POSSIBLE THAT THE PLUGIN MADE AN AUTOMATICALLY UPDATE OF THE CODE?
    WHAT MEANS THAT KIND OF MESSAGES?
    IT´S POSSIBLE THAT SOMEONE (SPAMMER OR ROBOTS) MANIPULATING MY CODE?

    https://wordpress.org/plugins/wordfence/

Viewing 6 replies - 1 through 6 (of 6 total)
  • Hi

    Can you post the differences? There should be a link to do that.

    One of the problems with wordpress plugins is that often authors don’t bother to do a proper release (showing the need for an update) and just edit the code directly in the repository. Since we mirror the wordpress.org repository if they do that without a release when you do a scan and come to our servers to get the code we see that your code is not the same code we have for the version of plugin you are using. The fastest way to confirm is to ask the author if he made changes, alert them to the fact that we see different files, and then hopefully they’ll do a proper release and resolve the issue. If they didn’t make the change or the code looks malicious then it is possible someone used an exploit into your site to change code. One of the things I like to do is to disable the theme and plugin editor in the admin section. http://www.wpbeginner.com/wp-tutorials/how-to-disable-theme-and-plugin-editors-from-wordpress-admin-panel/ Its not fool proof, but it will help. And if you think you have been hacked please follow the instructions here:
    http://docs.wordfence.com/en/My_site_was_hacked._How_do_I_use_Wordfence_to_clean_it%3F

    tim

    Moderator Jan Dembowski

    (@jdembowski)

    Forum Moderator and Brute Squad

    Can you post the differences? There should be a link to do that.

    Can you post the differences with a pastebin.com link? 😉

    Posting large amounts of code can get messy in the forums.

    Sorry, Jan. That’s what I meant and what I get for answering forum posts first thing in the morning. 🙂
    tim

    Maybe I can chime in here Tim.

    I also use this calculated fields form plugin and have had warnings from the Wordfence scan reporting that several of the plugin’s files did not match those in the repository.

    After checking the differences using the file comparison feature in Wordfence, I concluded that these changes were benign, and that as Tim highlights, were the result of the plugin developer making changes to the official version without updating the plugin version and changelog.

    I have reported this to the developer:
    https://wordpress.org/support/topic/wordfence-highlighting-modified-plugin-files?replies=5

    If this is also the case for @giulianag, then it wouldn’t do any harm for you to let the plugin developer know that this is happening for other users with both Wordfence and their Calculated Fields Form plugin installed.

    @Barnez – again, spot on 🙂

    Always try and let the plugin developer know. Sometimes its just inexperience or not thinking about how it affects security that the developer hasn’t thought of. I know one of the things WF values is customer suggestions. Some of the best ideas come from your thoughts. I’m sure the dev, if they were smart, would agree.

    tim

    Thread Starter giulianag

    (@giulianag)

    Thank you very much for your responses. very useful! 🙂

Viewing 6 replies - 1 through 6 (of 6 total)

The topic ‘WARNING MESSAGE – Modified plugin file’ is closed to new replies.