ManageWP flagged tagDiv Composer 3.5 as vunerable – possibly incorrectly.

Posted in: Newspaper
Post count: 24

Hi,

We use ManageWP on our client’s site, which scans the site daily for vunerabilities. We were notified that the tagDiv Composer v3.5 has a vunerability (see screenshot here).

However, if we expand it, it says: “WordPress tagDiv Composer plugin < 3.5 – Unauthenticated Account Takeover vulnerability”. We read that as versions before 3.5 are vunerable, yet we are running version 3.5 and yet it’s still been marked as vunerable.

Of course, we want to be sure – did ManageWP perhaps display this in error?

Thanks.

Post count: 27744

Hello,

This problem was solved in Newsapepr v12.1 -> https://wpscan.com/vulnerability/993a95d2-6fce-48de-ae17-06ce2db829ef, but as certain security plugins detect plugin version < 3.5, the problem was in 3.4. To solve the problem with <3.5 we changed the version to 3.6, all you have to do is delete tagDiv Composer and reinstall it from Newspaper > Plugins.

Thank you!

Post count: 24

Hi Anamaria,

Thanks for letting us know. 🙂

Viewing 3 posts - 1 through 3 (of 3 total)
The forum ‘Newspaper’ is closed to new topics and replies.