-
A vulnerability was found in premium kaswara plugin that allows you to upload malicious code through presumably via icon loader .
Please check the folders
/wp-content/uploads/kaswara/icons/
if you find any php files, then your site has been hacked . You need to start the cleanup process immediately or use a “clean” backup .Unfortunately, there is no response from the author of the plugin, but we have released an update that should eliminate the possibility of uploading malicious PHP files .
To update, remove the old version completely and install the plugin again in the required plugins in Appearance – Install Required Plugins – Kaswara – Install and Activate
or DOWNLOAD LATEST VERSION HERE .Thanks
Hi,
my site has been infected. Among the many redirects I discovered one in Kaswara -> Custom Settings -> Custom JS code that made me crazy.
I removed plugin but directory remains … I have to delete it?
Thanks.
The link does not explicit mention Font Icons Loader but seems to speak about the whole Kaswara plugin
“To update, remove the old version completely and install the plugin again in the required plugins .”
So i removed the old version but i am not finding the plugin to reinstall. Please any help?
I did what you suggested and my backend has changed. Find a picture of how it looks attached.
Attachments:
You must be logged in to view attached files.Make sure that you have installed the kaswara plugin . Thanks
Hello, My site http://www.autoquintagrande.com/auto-quinta-grande-2/ has affected with the plugin Kaswara – Wp Bakery Builder
Can I re-install a new version of the Kaswara plugin without a problem?
Does not appear on the panel as the required plugin…
Thanks
giova.licata
Just delete this code .
ana.neves
I gave all the instructions at the beginning of the post, please follow them .
Thanks
Hi Alex,
yes I deleted it yesterday … but should be there a dirty code that add it again …
I’m finding it …
You need to start the cleanup process immediately or use a “clean” backup .
Thanks
Скажите, пожалуйста, где взять отдельно плагин kaswara модифицированный? Если удалить весь wp bakery , сайт сыплется и весь внешний вид будет порушен.
ikoroleva781
Мы не просим удалять wpbakery а просим переустановить kaswara .
Спасибо
Make sure that you have installed the kaswara plugin . Thanks
Please i have installed the Kaswara already. Version 2.3.4
Мы не просим удалить wpbakery а просим переустановить касвару.
В моих плагинах нет wp bakery visual composer 4.1.1…
Есть только WPBakery Page Builder 6.4.0
buro86
I understand your frustration but our template was created 5 years ago and we are still releasing updates, unfortunately, we do not know what will happen to any of us in 5 years, as well as with any other plugin that we use .
You can disable this plugin it does not affect the basic operation of the theme .
Thanks
ikoroleva781, dziebenson
If you have support, then do not use this topic so as not to clog it, but create your own private topic . This topic is intended for those who have ended the support period .
Thanks
Surely no one can know the future in advance but as buro86 says the kaswara plugin no longer seems supported so you should remove it from your themes … you are selling them now and not 5 years ago.
Please we need support to totally disable kaswara plugin … which plugin should I uninstall?
I think disabling kaswara may cause site inconvenience.
Thanks
giova.licata
If you have support, then do not use this topic so as not to clog it, but create your own private topic and get help . This topic is intended for those who have ended the support period .
Thanks
Hi,
my website has been hacked by kaswara plugin.
I try to reinstall the AutoZone Theme, and it’s almost done, but I can’t install some needed plugins like : Kaswara, pix-auto-deal, pix theme-customHowever i have my activation key but it’s doesn’t work.
Could you help me please
thank you
Private Content Hiddenassistanceweb
Please extend your support period and our team will help you . Thanks
There is no reason for us to be the most affected by this situation and still have to pay support for a plugin required by the theme
ana-neves
You don’t need to pay extra for anything but if you can’t do it yourself then you need to extend your support period regardless of the situation as we have given all the instructions to solve this problem and we are also not happy that this has happened but we can’t help to 1 thousand buyers at a time . Thanks
Hi Alex, sorry but i don’t get your aurgument.
My/our sites have been hacked because your plugin had a serious exploit, so you have to support us solving the problem not only posting a old video with WordPress version 4.5.
I did everything you suggest in that video but it absolutly didn’t solve the problem.
This is my site with the plugin disabled: https://i.imgur.com/lwgRtUh.png
This is the WPBakery plugin that i deleted and reinstalled: https://i.imgur.com/qaqpeVt.png
This is the version of Kaswara plugin i had on my site: https://i.imgur.com/3RPlq0Q.png
I did the same to Kaswara plugin, so deleted it, but i can’t install it again through “Install required plugins” because it returns “Not Found”! https://i.imgur.com/Qmf4Fxj.png
So please, this is a big damage to my site, can you help updating a working solution?
This is the WPBakery plugin that i deleted and reinstalled: https://i.imgur.com/qaqpeVt.png
You do not need to remove the WPBakery plugin, you need to do the same thing with the KASWARA PLUGIN . Please just be more careful https://take.ms/qpiuB
Thanks
I already tried that, when i press Install Kaswara plugin in “Install required plugins” it returns: Not Found.
Same situation with me i can´t install kaswara plugin and I have problems with license key like assistanceweb referred
fabiomusicco
How about update and use latest theme version ?
ana-neves
Everyone has a different situation and if you are more detailed it will help to solve the problem more quickly .
Thanks
Dear Alex,
Same problem for me, and my support has expired 3 days ago, right after the spam started…
Kawsara doesn’t work, License wont be accepted even though I contacted our WebHost to handle the situation…
Please help !
tdluxe
Please follow the instructions at the beginning of the topic .
Thanks
ALSO PEOPLE CHECK YOUR ACCOUNTS FOR CLIENTS WITH GOOGLEGATEDPROJECT IN IT!!! THEY ARE MALICIOUS!
TIP USE OTP
You must be logged in to reply to this topic.