Close Menu
    Facebook X (Twitter) Instagram
    Trending
    • The Top 10 Newsletter Strategies to Boost Your Engagement and Reach
    • The Ultimate Cheat Sheet to Holiday Advertising in 2025
    • Data, AI, and the New Era of Creator-Led Growth
    • A Comprehensive Guide to the Future of Influencer Marketing 2025–2026
    • 18 AWeber Alternatives: Our Top Choice Revealed
    • 15+ ConvertKit Alternatives That Deliver Better Results
    • 16 Best GetResponse Alternatives (Tried & Compared)
    • We Tested 15+ SendGrid Alternatives – Discover the #1 for 2025
    YGLuk
    • Home
    • MsLi
      • MsLi’s Digital Products
      • MsLi’s Social Connections
    • Tiktok Specialist
    • TikTok Academy
    • Digital Marketing
    • Influencer Marketing
    • More
      • SEO
      • Digital Marketing Tips
      • Email Marketing
      • Content Marketing
      • SEM
      • Website Traffic
      • Marketing Trends
    YGLuk
    Home » SEO
    SEO

    WordPress Site Builder Addon Allegedly Adds “Backdoor” To Disable Websites

    YGLukBy YGLukMarch 17, 2024No Comments8 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email


    A extensively used add-on plugin for a well-liked WordPress web site builder put in an anti-piracy script that primarily unpublishes all posts. WordPress builders are furious, with some calling the script a malware, a backdoor,  and a violation of legal guidelines. The writer of the positioning builder addon purposely added the backdoor to be able to disrupt the web sites of those that use pirated variations of their plugin.

    Up to date: Plugin Developer Apologizes

    The plugin developer who was accused of purposely making a backdoor in his plugin wrote a public apology.

    He wrote:

    “My intention in implementing controversial code throughout the plugin was solely to fight the difficulty of piracy I’ve been dealing with. Nonetheless, I now notice that this was not the fitting method. My try to safeguard my work has sadly backfired, inflicting hurt and frustration to reliable customers of the plugin.”

    Up to date: New Data About Plugin Backdoor

    A post within the Dynamic WordPress Fb group (and a corresponding YouTube video) by Emil Trägårdh shares outcomes of a evaluate he did of various variations of the plugin that have been submitted to him.

    Emil wrote the next about his findings (spelling corrected):

    “Some individuals despatched me the code. I acquired 4 completely different variations.

    1.5.18 (comprises malware)
    1.5.19 (edit: additionally comprises malware, however its moved location)
    1.5.20 (edit: additionally comprises malware, however moved once more)

    I discovered a persistent backdoor that calls residence each third hour and executes any command that it receives straight to WP database.”

    I communicated by e mail with Emil Trägårdh who supplied extra particulars of his findings.

    He wrote of his discovery:

    “It’s designed to run any SQL command, however it may be used to focus on wp_posts. The command is about by distant supply. So the command could be modified at any time.

    Within the video I present DROP TABLE wp_users; Nevertheless it may also be used to insert a brand new admin account and execute PHP.”

    Emil additionally emphasised the caveat that the code he examined was offered by others for him to evaluate, that he didn’t himself obtain the code himself.

    He wrote:

    “I acquired the supply code that I examined from third events who mentioned they downloaded the plugin from official developer sources.”

    BricksUltimate Add-On For Bricks Builder

    Bricks web site builder is a web site constructing platform for WordPress that’s wildly well-liked with net builders who cite the intuitive consumer interface, the class-based CSS and the clear excessive efficiency HTML code it generates as options that elevate over many different web site builders. What units this web site builder aside is that it’s created for builders who’ve superior abilities, which permits them to create nearly something they need with out having to combat towards built-in code that’s created by typical drag and drop web site builders which can be meant for non-developers.

    A advantage of the Bricks web site builder is that there’s a neighborhood of third-party plugin builders that extends the ability of Bricks to make it quicker so as to add extra web site options.

    BricksUltimate Addon for Bricks Builder is a third-party plugin that makes it simple so as to add options like breadcrumbs, animated menus, accordion menus, star scores and different interactive on-page parts.

    It’s this plugin that has stirred up controversy within the WordPress developer neighborhood by including anti-piracy parts that many within the WordPress neighborhood really feel is a “very unhealthy follow” and others referring to it as “malware”.

    BricksUltimate Anti-Piracy Measures

    What’s inflicting the controversy seems to be a script that checks for a legitimate license. It’s unclear precisely what’s put in, however in keeping with a developer who examined the plugin code there seems to be a script put in that’s designed to cover all posts throughout your entire web site if it detects a pirated copy of the plugin (extra about this under).

    The developer of the plugin, Chinmoy Kumar Paul, downplayed the controversy, writing that individuals are “overreacting”.

    An ongoing discussion in the Dynamic WordPress Facebook group in regards to the BricksUltimate anti-piracy measure has over 60 posts, with the overwhelming majority of posts objecting to the anti-piracy script.

    Typical reactions in that dialogue:

    “…hiding a backdoor that reads the consumer database, is itself a breach of belief and reveals malicious intent on the developer’s half.”

    “I merely refuse to help or advocate any developer who thinks they’ve the fitting to secretly add a malicious payload to a chunk of software program. After which, as soon as confronted defends it and sees no flawed. Completely not acceptable and I’m glad the neighborhood has clubbed collectively stating that such an method shouldn’t be tolerated…”

    “…the actual fact the code is there’s horrible. I might not let any plugin with that kind of again door on any web site, not to mention anybody doing it for a consumer web site. That spoils the plugin for me absolutely!”

    “This dude right here and his firm might be simply reported and uncovered to the The Basic Knowledge Safety Regulation Authority (GDPR) in any EU nation for injecting an undeclared “monitor” code that has a non approved entry to DB’s and really behaves like malware!!!!!! is simply unbelievable! “

    One of many builders within the Dynamic WordPress Fb neighborhood reported their findings of what the anti-piracy script does.

    They defined their findings:

    “Me and my colleague have investigated this. Granted, we aren’t backend specialists. Our findings are that the plugin has an encoded code that isn’t human-readable with out decoding.

    That code is a further distant license test. If it fails, it appears to exchange values within the wp->posts database, primarily making all posts from all submit sorts unreadable to WordPress.
    It doesn’t appear to delete them outright as first suspected, but it surely does seem as deleted on the frontend for any non-expert consumer.

    This appears to be carried out in 1.5.3+ BU variations and as there aren’t any posts right here about it from legit customers, I are inclined to belief Chinmoy that it’s impossible to have an effect on legit customers.

    Now, my colleague certainly had a pirated model of the plugin, however sadly, she wasn’t conscious of it as a result of it was bought as a reliable model from a third-party vendor.”

    Response From the BricksUltimate Developer:

    The developer of the plugin, Chinmoy Kumar Paul, posted a response within the BricksUltimate Fb group.

    They wrote:

    “Re: Some coders are bypassing the license API with some customized code. That point plugin is activating and it’s easily working. My script is simply monitoring these websites and checking the license key. If not match, is deleted the info. However it’s not the perfect answer. I used to be simply testing.

    Subsequent time I shall enhance it with different logic and assessments.

    Persons are simply overreacting.

    I’m nonetheless looking for the perfect answer and updating the codes as per my report.

    …A whole lot of undesirable customers are submitting the difficulty by way of e mail and I’m shedding my time for them. So I’m simply looking for the most suitable choice to keep away from this sort of factor.”

    A number of BricksUltimate customers defended the plugin developer’s try to combat again towards customers with pirated copies of the plugin. However for each submit defending the developer there have been others that expressed sturdy disapproval.

    Developer Backtracks On Anti-Piracy Measure

    The developer might have learn the room and seen that the transfer was extremely unpopular. They mentioned they’d reversed course on taking motion.

    They insisted:

    “…I said that I shall change the present method with a greater possibility. Individuals don’t perceive the idea and unfold the rumors right here and there.”

    Backdoors Can Lead To Fines And Jail

    Wordfence lately revealed an article about backdoors left by builders that deliberately intrude with or harm a web site by publishers who owe them cash.

    In submit titled: PSA: Intentionally Leaving Backdoors in Your Code Can Lead to Fines and Jail Time they wrote:

    “One of many largest causes an internet developer could also be tempted to incorporate a hardcoded backdoor is to make sure their work is just not used with out cost.

    …What needs to be apparent is that deliberately damaging a web site is a violation of legal guidelines in lots of international locations, and will result in fines and even jail time. In america, the Pc Fraud and Abuse Act of 1986 (CFAA) clearly defines unlawful use of laptop programs. In response to 18 U.S.C. § 1030 (e)(8), merely accessing laptop programs in a manner that makes use of larger privileges or entry ranges than permitted is a violation of the legislation. Additional, deliberately damaging the system or information can also be a criminal offense. The penalty for violating the CFAA can embody sentences 10 years or extra in jail, along with massive monetary penalties.”

    Preventing piracy is a reliable situation. Nevertheless it’s somewhat tougher within the WordPress neighborhood as a result of WordPress licensing specifies that all the pieces created with WordPress have to be launched with an open supply license.

    Learn the plugin developer’s apology:

    An Open Apology and Immediate Rectification

    Featured Picture by Shutterstock/malidinc



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    YGLuk
    • Website

    Related Posts

    Using Google Merchant Center Next For Competitive Analysis

    December 2, 2024

    The Definitive Guide For Your Online Store

    December 2, 2024

    Bluesky Emerges As Traffic Source: Publishers Report 3x Engagement

    December 2, 2024

    Google Chrome site engagement service metrics

    December 2, 2024
    Add A Comment
    Leave A Reply Cancel Reply

    18 + eleven =

    Top Posts

    The Top 10 Newsletter Strategies to Boost Your Engagement and Reach

    November 9, 2025

    The Ultimate Cheat Sheet to Holiday Advertising in 2025

    November 7, 2025

    Data, AI, and the New Era of Creator-Led Growth

    November 7, 2025

    A Comprehensive Guide to the Future of Influencer Marketing 2025–2026

    November 7, 2025

    18 AWeber Alternatives: Our Top Choice Revealed

    November 7, 2025
    Categories
    • Content Marketing
    • Digital Marketing
    • Digital Marketing Tips
    • Email Marketing
    • Influencer Marketing
    • Marketing Trends
    • SEM
    • SEO
    • TikTok Academy
    • Tiktok Specialist
    • Website Traffic
    About us

    Welcome to YGLuk.com – Your Gateway to Digital Success!

    At YGLuk, we are passionate about the ever-evolving world of Digital Marketing and Influencer Marketing. Our mission is to empower businesses and individuals to thrive in the digital landscape by providing valuable insights, expert advice, and the latest trends in the dynamic realm of online marketing.

    We are committed to providing valuable, reliable, and up-to-date information to help you navigate the digital landscape successfully. Whether you are a seasoned professional or just starting, YGLuk is your one-stop destination for all things digital marketing and influencer marketing.

    Top Insights

    The Top 10 Newsletter Strategies to Boost Your Engagement and Reach

    November 9, 2025

    The Ultimate Cheat Sheet to Holiday Advertising in 2025

    November 7, 2025

    Data, AI, and the New Era of Creator-Led Growth

    November 7, 2025
    Categories
    • Content Marketing
    • Digital Marketing
    • Digital Marketing Tips
    • Email Marketing
    • Influencer Marketing
    • Marketing Trends
    • SEM
    • SEO
    • TikTok Academy
    • Tiktok Specialist
    • Website Traffic
    Copyright © 2024 Ygluk.com All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.