It happened again this morning.
The follow line of code is being injected into wp-includes/pomo/mo.php:
require_once dirname(__FILE__) . ‘/config.php’;
I just can’t figure out how they are doing it.
I believe it is maliciously, the one file changes every evening and wordfence tells me it does not match the wordpress core. One additional line is added.
I have already done all of this and it still doesn’t work. Where do I go to ask about the pro version?
I suppose the responsive theme could be affecting it.
It displays fine in all other browsers, even safari for mac.
Is there a way I can send the link directly to you. The site is still being developed and would like to keep the url private.