TagDiv Composer 4.0 being flagged as vulnerable by Patchstack

Posted in: Newspaper
Post count: 7

Hi,

I was wondering when an update to the TagDiv composer plugin would be available as it is being flagged as being vulnerable by Patchstack: https://patchstack.com/database/vulnerability/td-composer/wordpress-tagdiv-composer-plugin-4-0-reflected-cross-site-scripting-vulnerability?_a_id=350

Looks like a bad one so I’m keen to get this fixed on the site.

Thanks

Post count: 27744

Hi,

Please deactivate, delete, and reinstall tagDiv Composer from Newspaper plugins => https://www.screencast.com/t/OrzLvR2j and clear all cache.
There was no issue, there were issues with the plugin version only https://forum.tagdiv.com/topic/jetpack-alert-about-td-composer-vulnerability/

Thank you!

Post count: 7

Sorry I’m not sure how that will work. I will still be installing the same version. I currently have v4 and you want me to delete it an reinstall v4, surely that will mean it will have the same vulnerability flagged up?

This is a client site so I need to provide assurances that there is no XSS vulnerability.

Thanks

Post count: 27744

Hi,

Please let me know what version of the theme do you have.

Thank you!

Post count: 7

v12.3.1

Post count: 27744

Hi,

If you will do the above steps, the version will be 4.1

Thank you!

Post count: 7

Than you I have done that now.

Viewing 7 posts - 1 through 7 (of 7 total)
The forum ‘Newspaper’ is closed to new topics and replies.