Malicious Code in WordPress Template

I downloaded this template http://www.wordpresstemplates.com/?s=professional+business from the site a while ago and used it on 2 different sites. One day I noticed at the very top of the header in small text it said “cannot connect to database”.

I thought to myself, that’s weird, if the site couldn’t connect the database it wouldn’t show up…so I didn’t think anything of it, but then the other day I was working on one of the sites and jacked up the CSS file (luckily) because then I saw at the top this link with the anchor text: “HGH”, I was like, WTF is that!

Upon further investigation and a lot of help from my php god programmer it was being called from 3 encrypted files: start_template.php, theme_license.php there was also a lines of code in header.php, functions.php and sidebar.php that were altered, see below:

I’ve had to delete the code because it was messing up the page; If you’ve downloaded the Professional Business WordPress template and you see those two files, send me a message and I can tell you how to fix it.

These are the files that were affected:

Header.php
Sidebar.php
Functions.php

Look for the part that has the 2 encrypted files.

The two encrypted added files:

start_template.php
theme_licence.php

Please repost this on your blog and help stop these douchebags from cheating their way through life!!!
The Crusade Continues!!

Share

Tags: , , , , ,

Leave a Reply