Newspaper crash

Posted in: Newspaper
Post count: 2

Hi, when I activate tagDiv Composer the site becomes inacessible for administrators. My Hosting (Hostinger) says that the tagDiv Composer plugin has a vulnerability, in fact when I force the deactivation of the plugin the site becomes accessible.

Here is the error: WordPress tagDiv Composer Plugin < 4.4 is vulnerable to Cross Site Request Forgery (CSRF)

Post count: 27744

Hi,

This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
I can offer an alternative recommendation if you prefer that we don’t inspect your theme files. You could consider downgrading the WordPress version using the WP Downgrade plugin, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Also, please make sure that you have the latest version 12.6.1

Thank you!

Viewing 2 posts - 1 through 2 (of 2 total)
The forum ‘Newspaper’ is closed to new topics and replies.