WordPress tagDiv Composer Plugin < 4.4 | built on 05.10.2023 12:50 is vulnerable to Cross Site Request Forgery (CSRF)
please fix the issue and give the new update in newspaper td-composer plugin.
Hi,
The latest version of the theme 12.6.1 is safe -> https://patchstack.com/database/vulnerability/td-composer/wordpress-tagdiv-composer-plugin-4-1-csrf-to-xss-vulnerability.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
I can offer an alternative recommendation if you prefer that we don’t inspect your theme files. You could consider downgrading the WordPress version using the WP Downgrade plugin, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Thank you!
Hi,
Normally, this notice should not longer appear, as you can see here is verified and fixed -> https://i.imgur.com/iAzhkjQ.png
Thank you!
I have installed “Newspaper 12.6.1” into my brand new refreshed website. My hosting provider is “hostinger.in”, but whenever td-composer is installed, my hosting security provider (powered by Patchstack) itself tells me that the plugin has a virus. Deactivate and delete the plugin.
There is no point in using this theme if you cannot remove this malware. We would prefer to choose other alternative themes.
So please let us know how we can get our refund.
We are also providing you the screen shot of our hosting dashboard, so please take it seriously. This is a question of security of our website
https://photos.app.goo.gl/HJbPieW8gPCjzRpF7
td-composer screenshort
-
This reply was modified 2 years by
Kailash Parihar.
Hi,
We communicated with a member of the Patchstack team and we checked the plugin, that’s why it appears verified and fixed there, so please contact your host to check the plugin once more together if they want with those from Patchstack.
You can request a refund here: https://themeforest.net/refund_requests/new, this request will be analyzed if the terms of use of the theme have been respected.
Thank you!
your taDiv td-composer is infected and vulnerable please recheck to your side for this plugin and release new update. I have given the link of screenshot below, please check it once and improve your product.
https://i.imgur.com/4Ko2xH0.png
https://i.imgur.com/2ygZ6Vf.png
https://i.imgur.com/QJHhIlo.png
https://i.imgur.com/7UHe6PX.png
https://i.imgur.com/ckVj5TW.png
Hi,
As you can see, the tagdiv Composer version is 4.4, and there is a version smaller than that is vulnerable, which means that you don’t have the latest version of the 12.6.1 theme, so please update, because the version 4.4 is verified -> https://i.imgur.com/sv01BCZ.png
Thank you!