Hello everyone,
Our website was built using SP Page Builder. About a month ago, the entire website was deleted. We restored it from a backup created one day before the deletion.
One or two weeks after the restoration, we began experiencing significant performance issues. The homepage was taking approximately six seconds to load. While investigating the cause, we found the following forum thread:
https://www.joomshaper.com/forum/question/45152
We suspected that both the website deletion and the subsequent performance issues might be related to the vulnerability described in that thread.
To address the issue, we took the backup created one day before the website was deleted and scanned it using the following Joomla security scanner:
https://github.com/zkrana/joomla-security-scanner
We deleted all malicious files detected during the scan. If I remember correctly, approximately one thousand files were identified. We also upgraded SP Page Builder from version 5.2.6 to version 6.6.2.
Since then, we have not experienced any further website slowdowns. However, several new issues have appeared.
First, the following text occasionally appears in the main menu:
current-item active">
Fixing this issue through the Joomla administrator panel only resolves it temporarily.
In addition, SP Page Builder has been inaccessible since last week. We are unable to create new pages or edit existing ones. When we open Components → SP Page Builder, the following error message appears:
Request failed with status code 404
We would appreciate your advice on the following questions:
Could these issues still be related to the vulnerability and the attack on the website?
Could this indicate that some malicious files or code remain on the server?
What steps would you recommend taking in this situation?