{"id":23175,"date":"2020-12-09T09:52:30","date_gmt":"2020-12-09T01:52:30","guid":{"rendered":"https:\/\/web.mwwsb.com.my\/pjci\/?post_type=kb&#038;p=23175"},"modified":"2022-09-08T21:26:05","modified_gmt":"2022-09-08T13:26:05","slug":"security-alert-spamming-issues-in-wordpress-platform-info","status":"publish","type":"kb","link":"https:\/\/www.casbay.com\/guide\/kb\/security-alert-spamming-issues-in-wordpress-platform-info","title":{"rendered":"Spamming in WordPress platform"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"23175\" class=\"elementor elementor-23175\" data-elementor-post-type=\"kb\">\n\t\t\t\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-9cc54b8 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"9cc54b8\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-3dee45c\" data-id=\"3dee45c\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e9f260d elementor-widget elementor-widget-heading\" data-id=\"e9f260d\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Spamming in WordPress platform<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2d4d6a7 elementor-widget elementor-widget-heading\" data-id=\"2d4d6a7\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-medium\">How To Fix the Spamming in WordPress?<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-01d93cf elementor-widget elementor-widget-text-editor\" data-id=\"01d93cf\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Be careful while selecting any free Premium WordPress Themes because the theme can be no doubt free but you don\u2019t know if it&#8217;s spam- or script-free too. Else you too will have to invest your time in researching the reasons like me or recovering your losses due to these scam scripts. In most cases, spam scripts are always there if you get a premium theme or plugin from the internet for free.<\/p><p>So, next time if you get any premium theme or plugins from the Internet for free make sure it is spam-, script-free. Otherwise, you have to pay much more than the original cost of the themes and plugins. As in the traditional way you check the theme with your anti-virus software and get a green signal \u201cNo Virus Detected\u201d. So you stop here and get it, but the reality is some spam scripts are not detected by anti-virus, google webmaster tools, or any WordPress security plugin.<\/p><p>Here is an example: I got an amazing impressive theme used by labnol for free. And the offer for me no doubt was like a \u201cBUMPER PRIZE\u201d. I tested it with anti-virus and Google fetch and it showed no error and according to me, I became a saver by saving $200. I was really happy with the theme and was using it over my official website. But after one month I realized that my traffic decreased by 80% !!! This was the time when I was to search for the reasons. Why is my traffic drowning at such a drastic rate\u2026?<\/p><p>If you are facing a similar kind of problem as above, do not worry. This tutorial will tell you how to find and fix the spam scripts in your theme or plugin.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2db1c95 elementor-widget elementor-widget-heading\" data-id=\"2db1c95\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Types of spam scripts in themes<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3bfac56 elementor-widget elementor-widget-text-editor\" data-id=\"3bfac56\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Scam Script implementation can be done in several ways.<\/p><ol><li>Some spam scripts are placed inside the theme or plugin for traffic and back link .<\/li><li>Other scripts can take control of your site and these are more dangerous as it can destroy your website or blog. Two ways how hackers place these scam scripts:<br \/>The hackers place spam scripts in either by <strong>javascript code<\/strong>\u00a0or\u00a0<strong>php code<\/strong>.<\/li><\/ol>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-524a244 elementor-widget elementor-widget-image\" data-id=\"524a244\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/casbay.com\/guide\/wp-content\/uploads\/2021\/02\/Encrypted-JavaScript-spam-script.png\" title=\"\" alt=\"\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-918b2d0 elementor-widget elementor-widget-text-editor\" data-id=\"918b2d0\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<figure id=\"attachment_5505\" class=\"wp-caption alignnone\" aria-describedby=\"caption-attachment-5505\"><figcaption id=\"caption-attachment-5505\" class=\"wp-caption-text\">Encrypted JavaScript spam script<\/figcaption><\/figure>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-490d7a2 elementor-widget elementor-widget-image\" data-id=\"490d7a2\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/casbay.com\/guide\/wp-content\/uploads\/2021\/02\/Encrypted-php-spam-script.png\" title=\"\" alt=\"\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-072d65d elementor-widget elementor-widget-text-editor\" data-id=\"072d65d\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<figure id=\"attachment_5506\" class=\"wp-caption alignnone\" aria-describedby=\"caption-attachment-5506\"><figcaption id=\"caption-attachment-5506\" class=\"wp-caption-text\">Encrypted php spam script<\/figcaption><\/figure>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f2fc4f3 elementor-widget elementor-widget-heading\" data-id=\"f2fc4f3\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Finding and removing spam script in WordPress themes and plugins, here's how:<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-75296e6 elementor-widget elementor-widget-text-editor\" data-id=\"75296e6\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Well, we need an IDE and there are some choices you can choose from. For example, <a href=\"https:\/\/notepad-plus-plus.org\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-wpel-link=\"external\">Notepad++<\/a>,\u00a0<a href=\"http:\/\/www.editplus.com\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-wpel-link=\"external\">Edit plus<\/a>,\u00a0or\u00a0<a href=\"https:\/\/www.eclipse.org\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-wpel-link=\"external\">Eclipse<\/a>. Whenever you download some suspicious themes or plugins extract them to your desktop. Please do the following steps:<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-44ac117 elementor-widget elementor-widget-text-editor\" data-id=\"44ac117\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ol><li>Firstly, <strong>open<\/strong> your <strong>IDE<\/strong>. I choose Notepad++ because of its light.<\/li><li>Next, go to search and click the \u201c<strong>Find in files\u201d menu<\/strong>.<\/li><li>Now Find in files Box will be open in Find What enter the keyword\u00a0<strong><em>eval<\/em>.<\/strong><\/li><li>Now <strong>choose your theme or plugin directory<\/strong>.<\/li><li>After that, click on <strong>find all<\/strong>.<\/li><li>If the result comes click on the link in the result bar. You will see the encrypted line.<\/li><li>Lastly, <strong>remove<\/strong> it.<\/li><\/ol>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1237425 elementor-widget elementor-widget-heading\" data-id=\"1237425\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Keywords\u00a0curl:<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8956b79 elementor-widget elementor-widget-text-editor\" data-id=\"8956b79\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Curl is a computer software project providing a library and command-line tool for transferring data using various protocolscurl has no use in your WordPress theme. Although some SEO plugins use curl for making a connection with a remote server. This method without a doubt will remove the encrypted script but my recommendation is that you use genuine plugins and themes. Hope this helped you solve the Spamming issues in WordPress CMS.\u00a0<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e342d04 elementor-widget elementor-widget-heading\" data-id=\"e342d04\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-medium\">To all WordPress platform users and administrators<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3dfbacb elementor-widget elementor-widget-text-editor\" data-id=\"3dfbacb\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Please be aware: Dear valued customers, our security team found that there is a high number of cases reported on Spamming from WordPress platform users. After further investigation and analysis of the reported cases, they found that the spammer is targeting WordPress core files, which is \u201c\/wp-includes\/\u201d folder as well as other Core WP folder: \u201c\/wp-content\u201d and \u201c\/wp-admin\u201d. The best way is to remove all the existing files from the hosting space and download the latest version directly from the WordPress website. It is not recommended to re-install using 3rd party clients, such as Softaculous or RVSiteBuilder, or any other similar applications.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Spamming in WordPress platform How To Fix the Spamming in WordPress? Be careful while selecting any free Premium WordPress Themes because the theme can be no doubt free but you don\u2019t know if it&#8217;s spam- or script-free too. Else you too will have to invest your time in researching the reasons like me or recovering [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"site-sidebar-layout":"no-sidebar","site-content-layout":"page-builder","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"disabled","ast-breadcrumbs-content":"","ast-featured-img":"disabled","footer-sml-layout":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"default","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""}}},"kbtopic":[43],"kbtag":[106],"mkb_version":[],"_links":{"self":[{"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kb\/23175"}],"collection":[{"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kb"}],"about":[{"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/types\/kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/comments?post=23175"}],"version-history":[{"count":13,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kb\/23175\/revisions"}],"predecessor-version":[{"id":36628,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kb\/23175\/revisions\/36628"}],"wp:attachment":[{"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/media?parent=23175"}],"wp:term":[{"taxonomy":"kbtopic","embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kbtopic?post=23175"},{"taxonomy":"kbtag","embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kbtag?post=23175"},{"taxonomy":"mkb_version","embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/mkb_version?post=23175"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}