Seems to be some dodgy files in Storefront on client site
-
Hi
I’ve installed Wordfence on a client site.
Wordfence seems to have picked up some dodgy files in Storefront on client site. Wordfence has picked up in storefront/assets/images/credits-cards/elastic-slider.php
and storefront/asets/images/admin/welcome-screens/wpzhijdengl.php which I assume are dodgy files.
..storefront/assets/images/customizer/starter-content-products/hoodie-with-zipper.php (seems dodgy also).
What about this one: storefront/assets/images/admin/welcome-screen/automattic.php ? Should that be there or dodgy ? Is there supposed to be an actual welcome-screen directory?
Seems to be some additional php flies that shouldnt’ be there in those directories ..
Can I just delete ALL files under the credit-cards directory, do I need them? I would rather delete if I can to remove the dodgy files,.
And it says this file is unsafe wp-content/themes/storefront/functions.php – CRITICAL
Especially under Storefront assets
Here is 1 error log
[18-Sep-2023 02:24:09 UTC] PHP Notice: Undefined offset: 0 in domain.com.au/wp-content/themes/storefront/assets/images/credit-cards/elastic-slider.php on line 1 [18-Sep-2023 02:24:09 UTC] PHP Warning: shell_exec(): Cannot execute a blank command in domain.com.au/wp-content/themes/storefront/assets/images/credit-cards/elastic-slider.php on line 1 [17-Jun-2024 01:59:01 UTC] PHP Notice: Undefined offset: 0 in domain.com.au/wp-content/themes/storefront/assets/images/credit-cards/elastic-slider.php on line 1 [17-Jun-2024 01:59:01 UTC] PHP Warning: shell_exec(): Cannot execute a blank command in domain.com.au/wp-content/themes/storefront/assets/images/credit-cards/elastic-slider.php on line 1
Storefront is at its latest version 2.4.6 (is that the latest version ?) so I cannot tell what directories or files are supposed to be there and which ones are dodgy files within STorefront files. There is no option to upgrade STorefront so I assume that is current version.
Website seems to have been partly compromised so I’m trying to find the dodgy files. Wordfence plugin is great at letting me know which files to look at that could have issues.
Can someone help and advise please on what is safe to REMOVE that shouldn’t be there in the STorefront files and directories please?
Is there somewhere I can look and compare what directories/files should be there and not be there?
Thanks Kristin
- You must be logged in to reply to this topic.