Elementor Sites Hacked Due to Zero Day Vulnerability

DerangedWolf

Elite Member
Jr. VIP
Joined
Apr 30, 2018
Messages
1,923
Reaction score
1,512
I am safe and my clients. I don't use that add-on.
I got that news on my google news feed yesterday.
 
Yes my website too got injected with Japanese Keyword Virus. We successfully managed to remove all the malware but there are way too many spam pages indexed on Google.

Screen Shot 2021-03-11 at 7.31.27 PM.png

Does anyone know how to remove these pages from Google index? We have tried using Google Search Console's "Removal feature" but when I try to submit a removal request for any of these spammy pages, GSC says, "URL not in property".

Any other solution?
 
I am safe and my clients. I don't use that add-on.

Is it the Elementor Pro addon? Because I am using it and my site it clean

Does anyone know how to remove these pages from Google index? We have tried using Google Search Console's "Removal feature" but when I try to submit a removal request for any of these spammy pages, GSC says, "URL not in property".

Manual removal using the Google Search console is your only bet. Also, scan your site using WordFence or Sucuri to make sure it's clean
 
And here people are concerned about nulled plugins...

This is the plugin that has the vulnerability and it's already been patched.
 
Yes my website too got injected with Japanese Keyword Virus. We successfully managed to remove all the malware but there are way too many spam pages indexed on Google.

View attachment 165999

Does anyone know how to remove these pages from Google index? We have tried using Google Search Console's "Removal feature" but when I try to submit a removal request for any of these spammy pages, GSC says, "URL not in property".

Any other solution?
Had a similar attack on my site, a few months back. All I did was cleaning the website and resubmit the sitemap. The spam pages were removed from the website. The indexed spam pages got removed from Google in a few weeks.
 
Is it the Elementor Pro addon? Because I am using it and my site it clean



Manual removal using the Google Search console is your only bet. Also, scan your site using WordFence or Sucuri to make sure it's clean
It's the elementor addon, the free version of addon is fine the paid version got problem. It's in that sej article. It doesn't matter if you are using elementor pro or free, issue is with that paid version of addon.
 
I read this news: The Plus Addons for Elementor Critical Vulnerability

I didn't take it seriously. But then I checked my Facebook and Reddit, and people are actually reporting that their sites are injected with some codes.

Are you all safe?

Well that sucks.

I am naturally skeptical of themes. I've posted about it several times. Even legit licensed themes have bit me in the past (e.g. the thumbnail vulnerability).

Fixing hacked sites sucks.

Fortunately most my clients use custom developed themes or themes that I've audited and tested myself. Still you're never safe bc one third party addon thing can lead to the whole thing crumbling.
 
Yes my website too got injected with Japanese Keyword Virus. We successfully managed to remove all the malware but there are way too many spam pages indexed on Google.

View attachment 165999

Does anyone know how to remove these pages from Google index? We have tried using Google Search Console's "Removal feature" but when I try to submit a removal request for any of these spammy pages, GSC says, "URL not in property".

Any other solution?
Brother don't worry about that... It will automatically removed submit a request on google
 
Had a similar attack on my site, a few months back. All I did was cleaning the website and resubmit the sitemap. The spam pages were removed from the website. The indexed spam pages got removed from Google in a few weeks.

Did you use the nulled version of the plugin?
 
One of my sites got hacked due to this. Two administrator accounts were added with blank usernames, a wp-inc.php file was added to the root directory and a folder with several malicious files in it was added to /all sub-folder. The website was then sending out spam calls to other websites.

To resolve the issue I installed the latest updates for WordPress core, removed elementor as I wasn't actually using it and then installed malcare just to be on the safe side.
 
I used it from Festinger's vault.

He doesn't do anything wrong with his items. But you should still report this to him. Maybe what he did to null the plugin left some kind of vulnerability behind
 
He doesn't do anything wrong with his items. But you should still report this to him. Maybe what he did to null the plugin left some kind of vulnerability behind
He's a trusted member here, and I use his vault majorly. But I will tag him here just in case @Festinger Though this issue was related to Elementor's old version itself.
 
He's a trusted member here, and I use his vault majorly. But I will tag him here just in case @Festinger Though this issue was related to Elementor's old version itself.

Thanks for the heads up. The download has immediately been replaced by the updated version without this vulnerability anymore.

Please note that this issue is not related to my services, but a mistake by the original developers, as @yeahhub already confirmed.

https://www.yeahhub.com/30000-sites-risk-plus-addons-elementor-wordpress-plugin-hacked/
 
Back
Top