iThemes security says deactivate tag div composer!

Posted in: Newspaper
Post count: 31

Hi

I’m concerned as iTheme Security says there’s an error that’s not yet patched and recommends deactivating the plugin.

If we do this then the website will not work. Can you advise urgently please?

Post count: 31

This is what it says. Please advise

PLUGIN
tagDiv Composer
PLUGIN SLUG
td-composer
VULNERABILITY
Cross Site Request Forgery (CSRF)
PATCHED IN VERSION
No Fix
SEVERITY SCORE
High
CVE
2023-39166

Post count: 21065

Hello!

The tagdiv Composer is the main plugin of the theme, so you shouldn’t deactivate it.
Please make sure the theme and plugins are up to date.

Thank you!

Post count: 31

Hi Bettina

I understand that I shouldn’t deactivate it but iThemes Security is saying that it has an unpatched Cross Site Request Forgery and the risk is High.

They are saying that the risk of hacking is so high that we should not have websites that use the composer.

Please advise when this will be patched.

IThemes security is well respected and is telling all their clients, free and otherwise, not to use your product.

Please advise when this risk is being patched.

Thanks

Post count: 31

The Ithemes security was yesterday, after the latest tag div update

Post count: 21065

Hello!

We will investigate it and if there is an issue from our side, then we will add the fix in one of the future updates.

Thank you for understanding!

Post count: 31

Thank you, can you give an indication of when it will be fixed as soon as you can. I have seen an uptick of people trying to get into my sites since the warning came out.

I don’t believe we have long before we need to decide whether to stay with tag div. This warning may well stop tag div from acquiring new customers or retaining them.

Please help

Post count: 21065

Hello!

I have no indication right now. I’ve just added the request to our list. There could be some false-positive warnings. Can you please provide some screenshots of the warnings you received?

Thank you!

Post count: 31

Yes of course. Where can I upload the picture?

However all the detail I have is already posted above

  • This reply was modified 3 years by Jude.
Post count: 21065

Hello!

A solution for sending a screenshot/video is this:
Download, capture, and send: https://www.techsmith.com/jing-tool.html
After making the screenshot, you will have a link; paste it here.

Thank you!

Post count: 31

On reflection a screenshot does not add anything – all the information is drawn from iThemes Security weekly report.

This is what they say about their report and what they have to say about this weeks:

Unpatched plugins and themes are the #1 reason WordPress websites get hacked. Our weekly WordPress Vulnerability Report covers recent WordPress plugin, theme, extension, and core vulnerabilities. Learn when to apply updates or replace software products that have unpatched vulnerabilities.

Since last week, 94 total vulnerabilities emerged in public disclosure. They may affect over 7 million WordPress sites. There are 56 plugin vulnerabilities with security patches, so run those updates!

Additionally, there are 35 plugin vulnerabilities and three theme vulnerabilities with no patch available yet.

If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories.

In that case, you should consider deactivation and removal in favor of alternative solutions.

This is the warning for this week on tagdiv composer:

PLUGIN
tagDiv Composer
PLUGIN SLUG
td-composer
VULNERABILITY
Cross Site Request Forgery (CSRF)
PATCHED IN VERSION
No Fix
SEVERITY SCORE
High
CVE
2023-39166

There is no patch available yet, deactivate.

This is a serious warning that goes out to all their customers. Please advise.

Thanks

Jude

Viewing 11 posts - 1 through 11 (of 11 total)
The forum ‘Newspaper’ is closed to new topics and replies.