Hack from Constructor Theme
Thank you for sharing such a good theme which I have been using it to develop about 20 or more corporate websites with Constructor Theme.
However, I wish to highlight to you my misfortune on Good Friday today which had turned out to be Black Friday to me because I have 10 websites with Constructor Theme were hacked.
The symptoms as follow:
- The wp-login username was changed to ‘admin’, irregardless how many different/unique usernames;
- The wp-login password had become clear text;
- Blank email address causing unable to send password-reset email.
- All these 10 hacked websites resided in the same account in a single shared hosting server.
Based on the server log, the hacking entry was this theme. Appreciate if you can have a re-look on the design of the theme because I am not good at coding so that the loophole(s) can be blocked.
Hope to see the next version with more security features included as soon as possible.
- The topic ‘Hack from Constructor Theme’ is closed to new replies.