My site is hacked, possibly through the TagDiv Composer plugin. How fix?

Posted in: Newspaper
Post count: 15

Hi. I have over the weekend gotten reports from several users that when clicking on links going to my page, they have been sendt to scam sites. With help I found this report that seems to be a good fit, saying that the Tag Div Composer has a vulnerability; “Tracked as CVE-2023-3169, the vulnerability is what’s known as a cross-site scripting (XSS) flaw that allows hackers to inject malicious code into webpages.”
https://arstechnica.com/security/2023/10/thousands-of-wordpress-sites-have-been-hacked-through-tagdiv-plugin-vulnerability/

The article also says that this has been fixed in an update of TagDiv Composer, and I have today updated my Newspaper theme. But will that fix the problem if I already have been hacked?

Post count: 35449

Hi Anne, that fix will only resolve the theme vulnerability, but if your WordPress is infected you’ll need to manually clean it.
– Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins and files;
– Delete the weird/unknown themes and users;
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)
– Update the theme to the latest version, Newspaper v12.2
If you have gone through the steps above and are still facing issues, don’t hesitate to contact us via email at contact@tagdiv.com. We’ll be ready to help you as soon as possible.
Thank you!

Viewing 2 posts - 1 through 2 (of 2 total)
The forum ‘Newspaper’ is closed to new topics and replies.