Viewing 8 replies - 1 through 8 (of 8 total)
  • The same thing happens to me.
    I suggest you to delete plugin and re-install WooThemes 1.4.2 version, and also change your administrator password on WP.
    Also have a look to your database.

    Thread Starter Daniel J. Lewis

    (@djosephdesign)

    I found something interesting. You know the WooThemes Helper that’s supposed to help with automatic updates? Well that plugin doesn’t update well on Multisite (ironic?), and I found a new version that includes: “Fix – Ensure there are no wp.org update clashes from products with same slugs.”

    Thus, it sounds like this plugin developer may have found a loophole to get people to switch to his plugin. But if you have WooThemes Helper (1.5.3 or later), it should prevent these malicious updates.

    … but it doesn’t. I updated and my WordPress is still offering to install this inferior plugin by the same name.

    Thanks to share this information with us.
    Do you have found any dirty action related to this plug-in? Looking into the code seems to me that there’s nothing to be scared for.

    Thread Starter Daniel J. Lewis

    (@djosephdesign)

    A plugin that pops up literally overnight on version 3.7, has no changelog, stole the update on thousands of users, and has horrible English does not win my trust.

    Yes this is for sure.

    Do you know which information WP pass to the server to get the update downloaded? Maybe WP pass some sensible data to the server? (maybe wootheme login information)
    … maybe nothing as it is through WP repository

    Thread Starter Daniel J. Lewis

    (@djosephdesign)

    I’m guessing it’s just a similarity of a plugin slug.

    WooThemes is quite horrible with their own auto update system. You have to install their helper plugin in order to receive plugin updates.

    Without that helper plugin, I think WordPress will automatically just the www.ads-software.com plugin repo for any plugins that match the plugin slug and offer that as an update.

    Look at that! We’re exposing a WordPress security hole right here!

    Thread Starter Daniel J. Lewis

    (@djosephdesign)

    … and the plugin is gone.

Viewing 8 replies - 1 through 8 (of 8 total)
  • The topic ‘Why did I automatically receive this plugin?’ is closed to new replies.