reflanary
Veteran
Just Getting Started
Member Likes (0)
I got a notice that 11 plugins were updated but all the updates are from mclemon.org. The plugins are Advanced Theme Switcher, Comments Plus, CustomPress, Directory, Lock, Posts, MarketPress, Popover Plugin, Pro Sites, Q&A, Set Password on WordPress Multisite and Wiki. Even if legit it does not look good. How do we protect ourselves?

Responses (41)
Member (joined January 2012) Likes (0)
Ok, now when I look at the Plugin information everything comes up in chinese. What's going on?
Member (joined January 2012) Likes (0)
I mean when I click on the View version details link.
Support Chimp (joined March 2010) Likes (0)
Hey reflanary.
I'm not sure I completely understand, could you please elaborate further?
Is mclemon your site? Or are you saying something is updated from there?
Which version of WordPress and the update plugin are you using so I can look?
Please include screenshots.
Take care.
Member (joined January 2012) Likes (0)
Sorry - I'm freaking out a little because it looks really strange. I'm using the latest version of WP. I have several installations, not all are giving me problems. For the 11 plugins that I listed updates are showing that they are available on two domains hosted at Inmotionhosting and on my local (pc) test installation. All agree as to the latest version of update. When I click on the link that says View version () details - where () is version number for the plugin - the information that shows is the same for every plug in but the information is for the wrong plug in - now it's showing info for wpStoreCart LLC. When I close the browser and log back in the info is different. I've never heard of McLemon.org or wpStoreCart. It's not happening at my account at PSEK, by the way. It's bizzare. Why on my local pc but not PSEK? I'm thinking some plugin I tested was compromised but have no idea how to find it.
Member (joined January 2012) Likes (0)
I'm pretty sure something got compromised - not sure how. The PSEK stuff was never transferred between machines which would explain why that site is fine. Problem probably is on the PC and then was uploaded via ftp.
Member (joined January 2012) Likes (0)
Think I figured it out. On the admin bar in the dashboard it shows the number of updates. You click on that and it shows all the plugins each with a link that says "View version details." If the details are not available it will throw garbage in. By the way, it does happen on the psek site.
Support Chimp (joined March 2010) Likes (0)
Hey again.
So this is only on your local install? So there is anyway I could see whats happening?
mclemon.org provide this plugin:
http://wordpress.org/extend/plugins/wp-unread-comments/
Do you use that one?
And this is wpstorecart:
http://wordpress.org/extend/plugins/wpstorecart/
Are you familiar with that?
Perhaps even if not activated, they are still in the plugins directory?
Take care.
Member (joined January 2012) Likes (0)
I've never seen these plugins and have never downloaded them. I'm pretty sure your descriptions are messed up somewhere. I don't think there is a virus - it's some glitch with Wordpress and the way it's looking for your descriptions.
Member (joined January 2012) Likes (0)
I'm going to bed - not going to worry about it - but thanks for getting back to me.
Support Chimp (joined March 2010) Likes (0)
Hey again.
So this is only on your local install? So there is anyway I could see whats happening?
Perhaps you could please also include some screenshots?
Thanks.
Member (joined January 2012) Likes (0)
Thanks for getting back to me. Actually it is happening on all of my installs, local pc, psek.com and inmotionhosting.com. If I access the sites from my Blackberry Playbook I see the same thing. I'll try to go through the steps:
Log into locally hosted (Microsoft WebMatrix), go into Dashboard, it shows 18 available updates. This is WordPress 3.3.1., so, it's the latest version. I have the WPMU DEV Update Notifications installed with my API. 15 of the updates are from WPMU - Advanced Theme Switcher, Affiliates, Comments Plus, Custom Press, e-newsletter, Events+, Friends, Lock Posts, Market Press, New Blog Templates, Pop up!, Q&A, Set Password, and Wiki. When I click on the link on top (on top of the Dashboard just below the IE9 menu bar) that has the "18", the list of 18 updates shows up. (I just added a screen shot-I don't see it so hope it shows). If I click on the link that says "View version 1.0.6 details" for Advanced Theme Switcher I get this: If I click on the link for Affiliates (View version 2.4.6 details) I get this: The same thing happens with every WPMU Dev update. If it's not from WPMU everything is fine. For example, the description for the BP Profile Search (View version 2.8 details) looks like this
Now the really freaky thing is that if I log out and wait a while, the descriptions will change. I don't know how long it will take - I just tried it and it still says "Easy FancyBox-in-a-Box" - I never had this on my machine, by the way.
I know it's weird. Again, it's happening on my local machine and at least three other sites that have never been merged. I don't know what to think about it. Hopefully the screen shots show. Let me know if you need anything else.
Member (joined January 2012) Likes (0)
Here are the screen shots - hope it works and they make sense.
Member (joined January 2012) Likes (0)
So now about 15 minutes later the description becomes as follows:
Member (joined January 2012) Likes (0)
Once again - this description is the same on the psek.com installation and on my WebMatrix installation.
Member (joined January 2012) Likes (0)
And one other observation, it appears I don't need to log out for the descriptions to change - just wait a while and I get this:
Code Monkey (joined June 2011) Likes (0)
Hi there,
This is very strange, could you provide the URL of one of your websites so I can take a look?
Have you tried a fresh install on a fresh domain with nothing else in the public_html folder?
Thanks!
Kind Regards
Coding-Monkey.
Member (joined January 2012) Likes (0)
I have an unfinished site on psek at goalparty.net (please - it's not finished and not ready for the public - just saying it's not going to look quite right). Everything seems to work on it.
Code Monkey (joined June 2011) Likes (0)
Hi there,
Thanks for the link, I checked it out, and it appears that it's loading a lot of the files from rocketscript, this normally indicates that is how Cloudflare loads Javascript files, but I have known it on a couple of my clients sites to not play well with it.
But I don't see Psek mention anything about using cloudflare.
Everything seems to work fine, have you checked your index.php file in your file manager? Check for base_64 encode or decode things like that, also your themes index file.
The strange thing is, it's also on your localhosting, do you transfer files between the two?
Where did you get your Zip of wordpress from?
Thanks!
Kind Regards
Coding-Monkey.
Member (joined January 2012) Likes (0)
The wordpress on the local machine was directly from Microsoft via WebMatrix - I had nothing to do with it. On the other hosts it was from either fantastico or softaculous (?) - so again, I had nothing to do with it. Some of the files on my local machine were downloaded via ftp from psek, while others were downloaded either from Wordpress, WPMU, BuddyDev. I'll do a fresh webMatrix install with some of the older versions of WPMU plugins downloaded directly from WPMU to see what happens. So no copying from other directories and only a few plugins. Give me a few.
Member (joined January 2012) Likes (0)
Ok, did a fresh WebMatrix install. The install created a new folder called Wordpress2. I downloaded the 2.0.4 version of directory and the WPMU DEV Update Notifications plugins directly from WPMUDEV.org. Then I copied the files into the wordpress2/wp-content/plugins. I activated WPMU DEV Update Notifications but not Directory. I did not add my API to WPMU DEV Update Notifications. When I click on the update description of Directory I get this:
Can't get any cleaner. Thought maybe it was my API so I didn't use it - still same problem.
Member (joined January 2012) Likes (0)
Just to be clear, the only plugins were Akismet, Directory, wpmudev-updates and Hello Dolly. WebMatrix was already installed but the other installs shouldn't mix. Aside from the two WPMU plugins nothing was added.
Member (joined January 2012) Likes (0)
On Cloudflare, I'm just experimenting - the site is not ready so I'm just playing around with it.
Code Monkey (joined June 2011) Likes (0)
Hi there,
Thanks for that, right this of course shouldn't happen,
I'm wondering if it's something to do with WebMatrix mabye, and I still see no reason why it's rocketscript like this
<script type='text/rocketscript' data-rocketsrc='http://goalparty.net/wp-content/plugins/bp-gtm-system/_inc/global.js?ver=3.3.1'></script>Somewhere, either through a plugin or your hosting, is using RocketScript, part of CloudFlare.
Do you mind if I provide you a fresh install of Wordpress on my own hosting, using a sub domain url? Then upload your plugins and see what happens.
Let me know, hopefully that will give a bit more insight into why this is happening for you.
Thanks!
Kind Regards
Coding-Monkey
Member (joined January 2012) Likes (0)
But it's not just WebMatrix - the problem is that it's going to Wordpress to get the description and Wordpress is retrieving garbage for a description. Those descriptions are not on the WPMUDEV server - they are on the Wordpress server. It's happening on all my sites so it can't be WebMatrix.
Member (joined January 2012) Likes (0)
If you do a WebMatrix install do you get the same thing? I'm thinking WPMU is not supplying Wordpress with the correct description so when it doesn't find it it just throws garbage in.
Member (joined January 2012) Likes (0)
It's also not Cloudflare since WebMatrix is only on my local machine - don't worry about the BP-GTM-System thing - the theme I'm using is requesting that file.
Code Monkey (joined June 2011) Likes (0)
Hi Reflanary,
I'm sorry but I can't test using WebMatrix, I'm on a mac right now, I use the same plugins as you on some of my websites, and the descriptions etc, come up as they should never had a problem.
Which leads me to believe it's either WebMatrix or Cloudflare, but unfortuntely I can't test using either of these methods as I don't have them :(
What happens if you do a clean install of Wordpress on the cloudflare hosting using the official download from http://www.wordpress.org/ ? Still the same problem?
Thanks!
Coding-Monkey.
Code Monkey (joined June 2011) Likes (0)
That was just one line I was pointing out, but at least your theme does use that. I'll take another look.
Kind Regards
Coding-Monkey.
Member (joined January 2012) Likes (0)
I don't want to mess with Cloudflare - it's really a pain because it takes more than a day for the changes to go through. Besides, the site on Inmotion does not use cloudflare and I see the same thing.
Code Monkey (joined June 2011) Likes (0)
Is the site on Inmotion the URL you gave me? Or is that something different?
Thanks!
Kind Regards
Coding-Monkey.
Member (joined January 2012) Likes (0)
So, I have three different set ups, one local, one on psek with cloudflare and one on Inmotion without cloudflare - all the same thing. Cloudflare takes a day for the dns records to change is what I meant when I said it was a pain.
Member (joined January 2012) Likes (0)
No, the site I gave you is on Psek. It's not host specific. Here's the problem I would have doing this on another site - I can only get your plugins by downloading to my machine, then I would need to upload them to the new site - I don't know how to get them into a site without me having to ftp them to the site from my machine. If you could tell me how that would save me a lot of time.
Code Monkey (joined June 2011) Likes (0)
Hi there,
You can download the plugins then upload in there zip form via Wordpress "add plugins" upload, browse (to look for your file) upload and activate, does that make sense?
I'm just anonther member here, not staff of any sort :) Just like trying to help people reslove their problems :)
Kind Regards
Coding-Monkey
Member (joined January 2012) Likes (0)
I can't find the WPMUDev plugins there - besides, they would already be the up to date versions so I would not be able to replicate the problem.
Code Monkey (joined June 2011) Likes (0)
What versions are you using?
Kind Regards
Coding-Monkey
Member (joined January 2012) Likes (0)
I only need Directory 2.0.4 to test it and WPMU Dev Notifications. I just tried it on an iPage site and same thing. Out of time - can't work on it anymore - I'm convinced that the descriptions don't exist on the Wordpress servers and that is the issue. Just doesn't look good, i.e., you kind of lose confidence.
Code Monkey (joined June 2011) Likes (0)
Hi,
Someone else please correct with me if I'm wrong, but Wordpress wouldn't have the descriptions for WPMUDEV plugins as they aren't on Wordpress.org, correct?
I now believe reflanary that is why this happens and that is where your problem lies, sorry I can't be of more help.
Kind Regards
Coding-Monkey.
Member (joined January 2012) Likes (0)
Well, and here is the real problem, is that if you click on the Install Now button on the window that pops up it does indeed install the incorrect plugin - I don't like this.
Code Monkey (joined June 2011) Likes (0)
Hi,
Give me about an hour, I want to test some things on a live install, I'll say what I find out.
Kind Regards
Coding-Monkey
Member (joined January 2012) Likes (0)
Yeah, I need to get some paying work done.
Support Chimp (joined March 2010) Likes (0)
Our new beta of the notifications plugin can auto install without download or FTPing plugins:
http://premium.wpmudev.org/forums/topic/wpmu-dev-dashboard-plugin-30-beta-update-notifications
Thats correct, well except for the lite plugins of course.
With regards to the rest of the issues I'm not Mac so can't test the Microsoft thing as my PCs are are still packed away at the moment. However the things I don't generally use is Cloudflare and Webmatrix.
I always download fresh files from wordpress.org and do a manual install. I may have missed it here, but did you try to manually install WordPress and does it still happen then?
Were all these installs initially set up with webmatrix and then moved to hosting?
Certainly odd behaviour as well. I'll ask a couple of others if they have seen this before.
Take care.
Become a member