Just checked on another site not updated the theme and core yet and it’s working fine
Just checked on another site not updated the theme and core yet and it’s working fine
I’ve never been able to post anything on the task-board, it asks me to sign in, when i’m already signed in!
Ok thats not a simple solution is it?? should have to g over to media, upload, copy URL add to description add a
etc etc
Oddly you being programmers, it’s a an easy add! You already add the top product description and under category etc
Theres no screen shot, it says it’s been removed
In simple terms I just considered that the custom header image, would be a header image which would appear above content of the category, so that way you can do branded banners for each category
Having to go via shortcode for static blocks is all too much work for just adding an image each time
I understand what your saying, just the outcome is the opposite of what seems to be being achieved, its not a custom page heading image, it’s a background for the breadcrumbs!
I also understand the advantage of having a header image, but the same one across all categories isn’t really a feature! makes the website looking very boring having the same image.
Having an option to set a category header and descriptions is a much better look
Not the greatest of answers, why would I want to setup a static block every time, oddly it says add customer header image and in the settings there is an option of where do you want the banner
But having to go off and create a static block and etc is a load of unnecessary work!
Hi, yes we do, however on this occasion wordfence doesn’t pick it up, it was only when going through deactivating plugins, when we deactivated the code lite plugin which was adding scripts to the site.
Sorry finally resolved, it was WP Code which had been hacked and code added
This issue has reappeared, has naything changed in the theme that might have brought this back?
Ideally as Twitter is fully rebranding, can you in the next update, just change the icon reference and change the word Twitter to X
if you make it a new selector, i’ll need to change all my websites using Xstore, which isn’t ideal.
I can’t, won’t let me post, keeps asking me to login, despite being logged in
Ok so what seems to be confusing here is, that the file always did work, I thought the file you sent, had some sort of different code etc, but the original one has always worked.
What appears to be happening is the file is being replaced with the one I sent you, if you review the file you should be able to see the malicious code that is scraping additional card details.
What I’m trying to say is, it only changes either xstore or xstore child themes, so is there an unknown vulnrability in the theme that is allowing a malicious code to be added
I initially noticed that the the double card fields disappeared everytime we updated the theme.
Is the permmisions on that file correct? can it be changed to still operate but to prevent outside amends? I don’t know if the file is being replaced or the malicious code is being injected into the file.
In private, the file thats works is the one you sent me
Hi, the file that works is either the original or the one you sent, this is then replaced with a scrapper type version.
It only appears to effect the child theme of xstore
how do I send you files, wetransfer won’t let me upload it
Ok so thinking it was working, but last night it got replaced again from the child theme
I’ve got a copy of the corrupt file if you want to see it?
Ok so it’s been replaced again, this time, the one in the Xstore theme and the one in the child theme got replaced, the main one in Woocommerce didn’t
Are these specific to Xstore as it’s seem to be a vulnerability within the xstore theme
Hi, Ok but where am I putting this? in the child theme or the xstore theme?
And when you say test, i assume you mean it will work, but i am to test if it gets overwritten?
Its not re-writing plugin files, it’s your theme which is having it’s file re-written.
I’ve already copied the original file from woocommerce and replaced the one in your theme, which I have to do in order to remove the issue.
Do I actually need this in the to Xstore folder?
I’ll try the child theme route and see if that makes a difference, but just to confirm you understand there is only one file within the Xstore theme that is being replaced
I need to re-open this ticket as this issue continues, interestingly it’s targeting the form-billing.php file within the Xstore theme, it replaces this file with it’s own and creates a double card entry, it appears to look like it’s scraping card details.
I can replace the file with a back up version, but 5-6 days later, it’s been replaced again
ironically we have do have a monitor, which just told us someone from Ukraine did just login
Video in private, it’s also been documented elsewhere in regards to theme issues, I tried their fix but it didn’t make a difference
Ok so turning off variations worked, but then thats not really an answer!!
Sure
Quforms prevents caching, which means quforms plugin is preventing the websites caching to work, so quform prevents caching on the website, from quforms, no caching, prevents caching, quforms.
set-cookie: quform_session_2bae9f89c87adad3df05af041d2299c1=tIi4hfjCSZQXXxiX87yofbCslBrb5BiQF8jkjoHg; path=/; secure; httponly; samesite=None
Need some urgency on this one please, the project is getting delayed
FTP In private
Yeh I have done, I managed to get on it in incognito browser, but can’t seem to get it to work on standard browser
I’ll keep trying
In private
Try selecting “Helvetica-Neue” the uploaded custom font’s
They won’t set, and the standard ‘Roboto’ is set via the “kirki-style.css1” file that is changing the fonts
Another wasted reply!!
“I can’t update fonts on the site”, I don’t know how to explain the problem any easier!
You want me to send screenshots of the font not updating?
Not always, it has to do one update before the next, it’s common if you are a couple behind