This is the technical support forum for WPML - the multilingual WordPress plugin.
Everyone can read, but only WPML clients can post here. WPML team is replying on the forum 6 days per week, 22 hours per day.
| Sun | Mon | Tue | Wed | Thu | Fri | Sat |
|---|---|---|---|---|---|---|
| - | 8:00 – 13:00 | 9:00 – 13:00 | 9:00 – 13:00 | 8:00 – 12:00 | 8:00 – 12:00 | - |
| - | 14:00 – 17:00 | 14:00 – 18:00 | 14:00 – 18:00 | 13:00 – 17:00 | 13:00 – 17:00 | - |
Supporter timezone: Europe/Zagreb (GMT+01:00)
Tagged: Bug
This topic contains 15 replies, has 2 voices.
Last updated by Bruno Kos 2 months, 3 weeks ago.
Assisted by: Bruno Kos.
| Author | Posts |
|---|---|
| November 14, 2024 at 1:36 am #16400366 | |
|
christopheF-5 |
Background of the issue: Symptoms: Questions: |
| November 14, 2024 at 7:50 am #16400925 | |
|
Bruno Kos WPML Supporter since 12/2018
Languages: English (English ) German (Deutsch ) French (Français ) Timezone: Europe/Zagreb (GMT+01:00) |
Hi, Thank you for contacting WPML support! I am checking this with our 2nd tier. Apart from our the above screenshots, is there maybe additional info on the exact code parts that are reported as being malicious? Regards, |
| November 14, 2024 at 9:23 am #16401395 | |
|
christopheF-5 |
Sorry, unfortunately it's not highlight the part of the code. |
| November 14, 2024 at 1:25 pm #16402731 | |
|
Bruno Kos WPML Supporter since 12/2018
Languages: English (English ) German (Deutsch ) French (Français ) Timezone: Europe/Zagreb (GMT+01:00) |
I see. We are checking with with our development team and will keep you posted. |
| November 18, 2024 at 6:14 am #16412836 | |
|
Bruno Kos WPML Supporter since 12/2018
Languages: English (English ) German (Deutsch ) French (Français ) Timezone: Europe/Zagreb (GMT+01:00) |
This issue has been escalated to WPML developers. I will keep this thread updated as soon as I get any new information from them! |
| December 24, 2024 at 2:09 am #16542252 | |
|
christopheF-5 |
Hi Team, Can you please update what's the status about this? It's been a month, and we keep receiving warning from the hosting provider, but didn't see any fix from your team. |
| December 24, 2024 at 7:23 am #16542765 | |
|
Bruno Kos WPML Supporter since 12/2018
Languages: English (English ) German (Deutsch ) French (Français ) Timezone: Europe/Zagreb (GMT+01:00) |
Our team of developers is actively working on this issue. However, it is quite complex and is planned to be addressed in WPML version 4.7. Currently, 4.7 is in its Beta 1 phase and is not recommended for production sites. Unfortunately, the solution for this issue is not included in the beta version. At this time, I’m unable to provide specific dates for when this will be fixed, as it depends on the release timeline for version 4.7, which has not been finalized yet. |
| January 23, 2025 at 3:28 pm #16628966 | |
|
Giuseppe Toto WPML Supporter since 12/2025 Languages: English (English ) Italian (Italiano ) Timezone: Europe/Rome (GMT+01:00) |
Hi ChristopheF-5, I am a developer from the WPML Team, and I am currently working on replicating the issue you reported. However, I need your assistance to proceed further. Could you please provide detailed steps to reproduce the issue? I have already set up an EC2 Alibaba instance with an enterprise account, with WordPress and WPML installed and configured. At this point, I need detailed guidance on how to correctly set up and run the web shell detection service. Please provide all the necessary steps to replicate this phase. Looking forward to your response. Best regards, |
| March 27, 2025 at 6:38 am #16866176 | |
|
christopheF-5 |
Hi Guiseppe, We did nothing about it actually, but just install the plugin. I think Aliyun just report that issue via scanning the plugins files. All the wordpress project with WPML plugin got that alert basically. |
| March 27, 2025 at 6:59 am #16866226 | |
|
Bruno Kos WPML Supporter since 12/2018
Languages: English (English ) German (Deutsch ) French (Français ) Timezone: Europe/Zagreb (GMT+01:00) |
Our developers are actively working on this and the solution may end up in WPML 4.7.3. |
| March 27, 2025 at 9:51 am #16867277 | |
|
Bruno Kos WPML Supporter since 12/2018
Languages: English (English ) German (Deutsch ) French (Français ) Timezone: Europe/Zagreb (GMT+01:00) |
We were able to replicate the issue and, based on our investigation, it appears this may be a "false positive" as outlined in Alibaba's documentation. Alibaba also provides guidance on how to manage such warnings, which can be found on hidden link At this point, we're still determining the best way to suppress or prevent this warning on our end. |
| March 28, 2025 at 1:45 am #16870709 | |
|
christopheF-5 |
Ok, thanks for that. |
| May 22, 2025 at 7:54 am #17059889 | |
|
Giuseppe Toto WPML Supporter since 12/2025 Languages: English (English ) Italian (Italiano ) Timezone: Europe/Rome (GMT+01:00) |
Hi Christopher, That said, I want to clarify that in our tests, the files you mentioned are correctly flagged as negative by the Alibaba scan tool now. However, we have noticed that the tool's behaviour is not consistently deterministic. Could you please confirm whether the alerts have disappeared on your end, after you installed the latest version of WPML? In any case, the solution bruno shared with you is still valid. Thanks |
| June 18, 2025 at 6:13 am #17144618 | |
|
nijunW |
Hi, I recently encountered the same issue: Alibaba Cloud reported Trojan files in I'm using WPML Multilingual CMS version 4.7.6. |
| October 3, 2025 at 9:12 am #17453930 | |
|
christopheF-5 |
Hi WPML team, We still keep receiving the same issue report, and it affects all of our clients websites that hosted on Aliyun, can you please fix it as soon as possible? Version: 4.7.6 Details: 发现后门(Webshell)文件 紧急 发生时间:2025-10-03 00:20:20 告警描述:检测模型在您的服务器上发现了一个可疑的Webshell文件,可能是攻击者成功入侵网站后为维持权限植入的后门文件。 异常事件详情 木马文件路径:~/wp-content/plugins/sitepress-multilingual-cms/vendor/wpml/fp/core/Logic.php 文件MD5:66c2cdf1beb4e6976d7b471401d55dc9 恶意文件SHA256:8b487efd66047ab854d7c47346042ffcb72aaef228b9d3b7a79909bc030a128f 首次发现时间:2025-07-23 13:17:27 更新时间:2025-10-03 00:20:20 文件扫描方式: 定时回扫 木马类型:Webshell 源文件下载:下载 恶意行为标签: 不确定值对抗绕过/任意PHP代码执行/分支对抗绕过 描述:WebShell检测是根据文件内容的威胁程度进行打分,这个文件具备了一定的危险功能,本身具有一定的危险特征,但并不完全保证一定是一个网站后门,也可能是一些包含可疑代码的正常网站文件。 处置建议:如果您确定这个文件确定为WEBSHELL,请将恶意代码注释掉。如果您确定为误报,可以在前台选择忽略、加白或者标记为误报按钮。 |
The topic ‘[Closed] WebShell fix’ is closed to new replies.

