Dear tagDiv Support,
I am using the Newsmag theme purchased through ThemeForest.
My ESET antivirus detects one of the tagDiv plugins as a potential threat. I would like to know whether this is a known false positive or if there is an updated version of the plugin that resolves this issue.
The detected plugin is: tagDiv Composer.
The antivirus reports the following threat:
HTML/Scinject.B trojan.
Could you please investigate this issue and let me know how I can safely resolve it?
If necessary, I can provide screenshots of the ESET warning and any additional information you may need.
Thank you for your assistance.
Kind regards,
Hi,
It’s a false positive most likely. I’ve downloaded the theme package from themeforest and scanned the composer with virus total, it’s in order -> https://prnt.sc/4iIOjqaTh7AZ I also scanned it locally with Bitdefender, it’s also in order. So it’s safe to say that the composer as provided in the theme package poses no threat.
Maybe the website itself is infected with malware. To know for sure you could test your website with this online scanner from Sucuri -> https://sitecheck.sucuri.net/ Or install the Wordfence plugin and scan the website files with it.
Thank you!
Wordfence should mark it as fixed soon. The issue affected the composer from the Newspaper theme, which was fixed -> https://patchstack.com/database/wordpress/plugin/td-composer/vulnerability/wordpress-tagdiv-composer-plugin-5-4-3-reflected-cross-site-scripting-xss-vulnerability
Today a new update was released for Newsmag -> https://tagdiv.com/newsmag/ The composer is now version 5.4.6. Please update the theme and it will be fine.
Hi Simion,
Thank you for the update. I have updated the theme and tagDiv Composer to version 5.4.3.7, cleared all site cache, and re-scanned the site. However, ESET antivirus is still blocking the website.
Could you please advise if there are any specific database tables or remaining cached elements I should check, or if this might be a false positive on ESET’s end that needs to be reported?
Thanks!
In the meantime I’ve got confirmation from Wordfence and WPScan that they acknowledged the issue was fixed:
https://wpscan.com/vulnerability/601ad8e7-0ebf-4726-bfcf-b27b9d109137/
Maybe your website has been infected with malware. Updating the theme won’t fix it. Please test the website with the Sucuri live scanner -> https://sitecheck.sucuri.net/
If it detects malware, then I strongly recommend to immediately install the Wordfence plugin -> https://wordpress.org/plugins/wordfence/ and scan the website with it as soon as possible -> https://www.wordfence.com/help/scan/ if you haven’t already.
Could you provide a link to the website?
Hi Simion,
The website URL is https://mraclin.hr/
I have already completed all of those steps:
Scanned the entire database for cpajoliette (0 results).
Replaced WordPress core folders (wp-includes, wp-admin).
Updated the theme and tagDiv Composer to the latest clean versions.
Checked all theme options, headers, and custom code sections.
Ran a full Wordfence scan and verified that the files and database are clean.
Despite all files and database records being clean, external live scanners (like Sucuri) still report the injected script on the front end. Could this be caused by how tagDiv Composer caches shortcodes/elements, or is there a specific theme setting/table where this script could still be cached?
Best regards,
Mladen
There’s still something wrong. The Sucuri test still finds this -> https://prnt.sc/FOt2OGWKnwhF
If I check in the homepage there is a raw HTML which loads this script -> https://prnt.sc/jTP0J5UTTi4R
So it seems to be in the page content. If you edit the homepage with the composer that raw HTML should be visible, it’s right at the top of the page in the first row. Could you please check there?
Hi Simion,
Thank you for pointing out the exact location.
I opened the homepage in TagDiv Composer and removed the malicious script as well as the entire Raw HTML element from the top row, then saved the page.
However, when I run the Sucuri scanner again, it still throws the “Warning: Malware Detected” alert.
Is it possible that TagDiv Composer’s internal cache / compiled page cache is still serving the old version of the homepage, or is there another place within the composer/theme options where this needs to be cleared?
Best regards,
Mladen
Did you rescan the website? -> https://prnt.sc/NrVG0T4YLivy If not, it displays the same results from the last scan. I scanned it now and it says that it can’t scan the website for some reason -> https://prnt.sc/pwJxUTCx8cC7
That script isn’t in the page anymore however, and since it was the only thing that was detected in the last scan, if it’s gone now, the website should be in order.
The composer doesn’t have a cache, if something is removed from the page, it’s removed from the page.
I believe the website is fine now.
