Hi,
Wordfence signaled today about this: tagDiv Composer Version: 5.4.5 has a security vulnerability.
Details here:
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/td-composer/tagdiv-composer-545-reflected-cross-site-scripting
Here is the alert:
https://www.pasteboard.co/9HSozTwjG8pN.png
Please advice,
Thank you,
-
This topic was modified 2 weeks by
costinr.
Just bumping to say we got a similar notice from Blogvault. Expediting this as a hotfix would be ideal if possible.
“The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link”
I saw the recent message stating that a fix for the td-composer vulnerability (v5.4.5) will be released “this week.”
Could you please provide an exact ETA for this update? My website’s files are being constantly modified and infected by attackers every single day because of this exploit. Dealing with this exact same hacking issue and restoring backups daily is becoming a massive problem for us.
We urgently need this security patch to secure our systems. Thank you.
The update will be available tomorrow, first thing. The package is almost ready.
@ferhatakbas
Is the website infected with malware? What files are being modified/infected because of the XSS issue exactly? Please install wordfence and scan the website if there are such issues.
This vulnerability from the composer is related specifically to the simplified button element -> https://prnt.sc/gvSvPHoOk3iV While this is a medium level vulnerability, even if the button is used in a page, there is very little risk of a website getting infected with malware because of it. I won’t get into more details about how it can be exploited, but again, the chances are very low. If your website is actually infected with malware, restoring backups won’t fix it, neither will updating the theme. Please use a security plugin like wordfence and scan the website’s files in and outside of the wordpress installation.
Thank you!
