Tagdiv virus

Posted in: Newsmag
Post count: 14

Dear tagDiv Support,

I am using the Newsmag theme purchased through ThemeForest.

My ESET antivirus detects one of the tagDiv plugins as a potential threat. I would like to know whether this is a known false positive or if there is an updated version of the plugin that resolves this issue.

The detected plugin is: tagDiv Composer.

The antivirus reports the following threat:
HTML/Scinject.B trojan.

Could you please investigate this issue and let me know how I can safely resolve it?

If necessary, I can provide screenshots of the ESET warning and any additional information you may need.

Thank you for your assistance.

Kind regards,

Post count: 9544

false positive

Post count: 20685

Hi,

It’s a false positive most likely. I’ve downloaded the theme package from themeforest and scanned the composer with virus total, it’s in order -> https://prnt.sc/4iIOjqaTh7AZ I also scanned it locally with Bitdefender, it’s also in order. So it’s safe to say that the composer as provided in the theme package poses no threat.

Maybe the website itself is infected with malware. To know for sure you could test your website with this online scanner from Sucuri -> https://sitecheck.sucuri.net/ Or install the Wordfence plugin and scan the website files with it.

Thank you!

Post count: 14
Post count: 21

its not a virus but a vulnerabilty …..

Post count: 14

While it might just be a vulnerability rather than a malware infection, ESET Antivirus continues to block access to my website.

Post count: 14
Post count: 20685

Wordfence should mark it as fixed soon. The issue affected the composer from the Newspaper theme, which was fixed -> https://patchstack.com/database/wordpress/plugin/td-composer/vulnerability/wordpress-tagdiv-composer-plugin-5-4-3-reflected-cross-site-scripting-xss-vulnerability

Today a new update was released for Newsmag -> https://tagdiv.com/newsmag/ The composer is now version 5.4.6. Please update the theme and it will be fine.

Post count: 14

Hi Simion,

Thank you for the update. I have updated the theme and tagDiv Composer to version 5.4.3.7, cleared all site cache, and re-scanned the site. However, ESET antivirus is still blocking the website.

Could you please advise if there are any specific database tables or remaining cached elements I should check, or if this might be a false positive on ESET’s end that needs to be reported?

Thanks!

Post count: 20685

In the meantime I’ve got confirmation from Wordfence and WPScan that they acknowledged the issue was fixed:

https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/td-composer/tagdiv-composer-545-reflected-cross-site-scripting

https://wpscan.com/vulnerability/601ad8e7-0ebf-4726-bfcf-b27b9d109137/

Maybe your website has been infected with malware. Updating the theme won’t fix it. Please test the website with the Sucuri live scanner -> https://sitecheck.sucuri.net/

If it detects malware, then I strongly recommend to immediately install the Wordfence plugin -> https://wordpress.org/plugins/wordfence/ and scan the website with it as soon as possible -> https://www.wordfence.com/help/scan/ if you haven’t already.

Could you provide a link to the website?

Post count: 14

Hi Simion,

The website URL is https://mraclin.hr/

I have already completed all of those steps:

Scanned the entire database for cpajoliette (0 results).

Replaced WordPress core folders (wp-includes, wp-admin).

Updated the theme and tagDiv Composer to the latest clean versions.

Checked all theme options, headers, and custom code sections.

Ran a full Wordfence scan and verified that the files and database are clean.

Despite all files and database records being clean, external live scanners (like Sucuri) still report the injected script on the front end. Could this be caused by how tagDiv Composer caches shortcodes/elements, or is there a specific theme setting/table where this script could still be cached?

Best regards,

Mladen

Post count: 20685

There’s still something wrong. The Sucuri test still finds this -> https://prnt.sc/FOt2OGWKnwhF

If I check in the homepage there is a raw HTML which loads this script -> https://prnt.sc/jTP0J5UTTi4R

So it seems to be in the page content. If you edit the homepage with the composer that raw HTML should be visible, it’s right at the top of the page in the first row. Could you please check there?

Post count: 14

Hi Simion,

Thank you for pointing out the exact location.

I opened the homepage in TagDiv Composer and removed the malicious script as well as the entire Raw HTML element from the top row, then saved the page.

However, when I run the Sucuri scanner again, it still throws the “Warning: Malware Detected” alert.

Is it possible that TagDiv Composer’s internal cache / compiled page cache is still serving the old version of the homepage, or is there another place within the composer/theme options where this needs to be cleared?

Best regards,

Mladen

Post count: 20685

Did you rescan the website? -> https://prnt.sc/NrVG0T4YLivy If not, it displays the same results from the last scan. I scanned it now and it says that it can’t scan the website for some reason -> https://prnt.sc/pwJxUTCx8cC7

That script isn’t in the page anymore however, and since it was the only thing that was detected in the last scan, if it’s gone now, the website should be in order.

The composer doesn’t have a cache, if something is removed from the page, it’s removed from the page.

I believe the website is fine now.

Post count: 14

Hi Simion,

Awesome news — the warning is completely gone and the site is clean now!

Thank you so much for your guidance and for pinpointing that exact Raw HTML element. Your help made all the difference in getting this resolved.

Viewing 15 posts - 1 through 15 (of 15 total)
You must be logged in to reply to this topic.