• Resolved grafica.villcom

    (@graficavillcom)


    My Host (Aruba Spa) blocked my Zakra website due to “themegrill-demo-importer” plugin vulnerability!

    They told us that “The vulnerability of the plugin allows unauthenticated users to delete both WordPress content and registered users”.

    [ Deleted ]

    Now we’re trying to contact the host and understand how to restore our website.

    Please, let us know what is the problem and check your plugin/theme.

    Thank you.

    • This topic was modified 6 years, 2 months ago by Jan Dembowski.
    • This topic was modified 6 years, 2 months ago by Jan Dembowski. Reason: Deleted link to emails
Viewing 4 replies - 1 through 4 (of 4 total)
  • Moderator Jan Dembowski

    (@jdembowski)

    Forum Moderator and Brute Squad

    Side note: don’t share emails, even images of emails on this site. That’s not needed and that has gone very badly before. You don’t need to prove that your host said anything to you.

    Hi @graficavillcom
    We’ve already fixed the problem in the Demo Importer plugin and released an update. If you’ve restored the site, you can delete the plugin or update to the latest version.

    Regards,
    Ashish S.

    Theme Author ThemeGrill

    (@themegrill)

    Hi @graficavillcom,

    Yes, we were reported about this security issue and have already fixed it immediately in our latest version 1.6.2 (released on Feb 16) and followed by version 1.6.3 with more security enhancement for ThemeGrill Demo Importer plugin. If this plugin in your site was not updated to latest version, bad people might have used it to reset your site, which likely seems to be what happened in your case.

    The best approach to tackle this issue is: please contact your hosting service provider and ask them to restore to last working backup they have. These days most hosting service provider do have this backup service. Once you do this, please delete/deactivate the ThemeGrill Demo Importer plugin if you are not using it, if you need to use it, please make sure you are using the latest version 1.6.3

    We would like to apologize for the inconvenience caused. As per our request, wordpress(dot)org plugin team has now helped us to auto-update all old versions to the latest version so more users are not affected by this. We as developers are working continuously to better handle this.

    Thanks.
    Sanjip S.

    Thread Starter grafica.villcom

    (@graficavillcom)

    Hi @themegrill and @themegrillteam,

    Thank you very much for the update and explanation!

    Sorry @jdembowski, I’ll keep it in mind for next posts, thank you.

    Kind regards

Viewing 4 replies - 1 through 4 (of 4 total)

The topic ‘Website blocked by Host for Vulnerability’ is closed to new replies.