For anyone who wants to use this plugin, be aware that there appears to be an exploit in the 'newsletter.php' file.
My site was attacked today, and looks like they were trying to send out mail via this page. I've now since deleted the page entirely.
Since it appears that Chriteris' demo site has been deleted again, and he hasn't been back here since he posted them. I don't think we'll be able to get any support from him.
Are there any other coders around, who would be willing to look at this theme and see if there are any other vulnerabilities anywhere?
I really like this theme, but it needs support.
EDIT:
Here is what my host had to say about this page
The individuals are setting their name as a URL/image and it's being linked and sent. Here's the header portion:
Code:
To: maticielma@wp.pl
Subject: Unsubscription needs confirmation
X-PHP-Script: www.caraudiocentral.net/forums/dbseo.php for 1.20.181.16
X-PHP-Filename: /home/caraudio/public_html/forums/dbseo.php REMOTE_ADDR: 1.20.181.16
From: "Car Audio Central - Anything and Everything car audio"
Auto-Submitted: auto-generated
Message-ID: <20201222005958.736a035a8187@www.caraudiocentral.net>
MIME-Version: 1.0
Content-Type: text/html; charset="ISO-8859-1"
Content-Transfer-Encoding: 8bit
X-Priority: 3
X-Mailer: vBulletin Mail via PHP
Date: Mon, 21 Dec 2020 16:59:58 -0800
Then the actual contents has something like this:
Dear [Malicious URL Here][Malicious Image]