Following a security vulnerability in the SP Page Builder extension and subsequent attacks - Forum | JoomShaper
Staff replied SP Page Builder

Following a security vulnerability in the SP Page Builder extension and subsequent attacks

Asked by Michał Helbin 1 month ago Last activity 1 month ago

Hello. Following a security vulnerability in the SP Page Builder extension and subsequent attacks, the site and its extensions were updated and further secured; however, the site has slowed down significantly. It turns out that during loading, it attempts to access multiple directories to load style.css.

Below are a link and a screenshot; naturally, these directories—such as /iconfont/icosfrdty/ and the subsequent ones—do not exist at that location:

How can I remove these erroneous references, and where might they be stored?

1 reply

Ziaul Kabir Staff
1 month ago · edited

Hello,

We sincerely apologize for the inconvenience caused.

This issue has been fixed from SP Page Builder v6.6.2. Once you upgrade to latest one, v6.8.0, this specific vulnerability can no longer be exploited.

However, if your site was compromised before upgrading, simply updating the extension will not remove any malicious files or backdoors that may have already been uploaded. If those files remain on the server, attackers may still be able to access your site. Therefore, it is important to perform a complete cleanup before considering the site secure.

Please, follow this documentation: https://www.joomshaper.com/documentation/sp-page-builder/troubleshooting#how-to-clean-an-infected-joomla-4x-6x-site

After completing the cleanup and upgrading to v6.8.0, please let us know the outcome or if you need any further assistance.

We'll be happy to help.
Thank you.

Log in to reply.