No search results were found in Documentation!
Hi,
Please update the theme to the latest version 12.6.5.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Thank you!
How to update my theme whitout changing anything on my website?
When tried to update it I lost anything. Can I simply change some files and update with the new one? My website is actually offline for a TagDiv malware problem.
Hello,
You have malware on the website. Please update the theme to the latest version 12.6.5.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Thank you!
Hello,
You have malware on the website. Please update the theme to the latest version 12.6.5.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Thank you!
Hello,
The theme has nothing to do with the htaccess file. I believe it’s just a coincidence. Please check if you have any other htaccess files or other strange files because then you might have malware.
Thank you!
Hello,
You have malware on the website. Please update the theme to the latest version 12.6.5.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Thank you!
The website is redirecting due to malware in the theme. The website is not opening properly as well.
Hope to hear from you soon as we are facing a lot of trouble.
Here is the URL for reference https://newsstore24.com/
On the only site I have tagDiv composer on (I have the Newspaper theme) I am experiencing malware banners when I activate it. Once deactivated I no longer have this problem.
I made sure my computer was clean with AdwCleaner and Malwarebytes. In any case, by deactivating the plugin all popups and malware tabs end immediately.
Plugin version: 2.3 built on 09.06.2018 22:20
Theme version: V 8.8.1
Can you investigate the issue?
Hello,
You have malware. Please update the theme to the latest version 12.6.5.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Thank you!
Hello,
Please let me know what theme version you have.
Please update the theme to the latest version 12.6.4.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Thank you!
Only in my mobile version it pops or redirect to spam website, in sourecode it shows the malware how to remove it and get back my website to normal. my website link https://www.lifeontwowheelsride.com
We had an old newspaper theme, got malware
we upgrade wordpress to 6.4.3
and tried to upgrade newspaper them, but we start getting these errors
Uncaught Error: Class ‘td_util’ not found in /var/www/html1/wp-content/themes/Newspaper/includes/wp-booster/wp-admin/tagdiv-view-header.php:19
Stack trace:
#0 /var/www/html1/wp-content/themes/Newspaper/includes/wp-booster/wp-admin/tagdiv-view-theme-plugins.php(59): require_once()
#1 /var/www/html1/wp-content/themes/Newspaper/includes/wp-booster/tagdiv-wp-booster-functions.php(499): require_once(‘/var/www/html1/…’)
#2 /var/www/html1/wp-includes/class-wp-hook.php(324): {closure}(”)
#3 /var/www/html1/wp-includes/class-wp-hook.php(348): WP_Hook->apply_filters(”, Array)
#4 /var/www/html1/wp-includes/plugin.php(517): WP_Hook->do_action(Array)
#5 /var/www/html1/wp-admin/admin.php(259): do_action(‘newspaper_page_…’)
#6 {main}
thrown in /var/www/html1/wp-content/themes/Newspaper/includes/wp-booster/wp-admin/tagdiv-view-header.php on line 19
[05-Mar-2024 20:03:34 UTC] PHP Parse error: syntax error, unexpected ‘)’ in /var/www/html1/wp-content/plugins/td-composer/legacy/Newspaper/includes/td_config.php on line 9062
Hi,
Usually this kind of situation appears on old theme versions that in time are exploits by bots to inject malwares.
The latest theme version is 12.6.4
Thank you!
After Theme Installation malcare said hack found in your site . But when i delete theme its clear .
Hello,
Can you please provide more details about your issue with screenshots or a video?
Also, for HTTP, you need to have a certificate for SSL. Also, check the site for malware https://sitecheck.sucuri.net/
Also, please do a test using only tagdiv plugins and check after.
Thank you!
Hello,
I recommend updating the theme to the latest version, 12.6.4 to be updated and to don’t have malware.
If you want to update the theme, you should download the latest version of it from Theme Forest account and download it.
I recommend that you update the theme manually https://forum.tagdiv.com/how-to-update-the-theme-2/ via FTP/cPanel/File Manager, also if possible disable extra plugins during the theme update to avoid any problems that may arise and make sure that you have activated the tagDiv Standard pack plugin to keep the website’s look. You can try to update the theme on a staging website.
After you update the theme, you need to update the theme plugins too.
In the worst cases, the settings in the theme panel may be lost (there have been isolated cases), in these cases, after the theme plugins that were previously used are activated, you will have to use a backup for the theme panel -> https://forum.tagdiv.com/import-export-theme-settings/
Thank you!
Hi,
Did you clean the files for malware?
Can you please provide the link to your website?
Thank you!
hello,
I would like to inquire about the resource consumption of CPU, RAM, and I/O usage on our website. I have scanned the website and disabled all the plugins. There is no malware detected after scanning it with Wordfence and other plugins. Additionally, I have removed all website files and uploaded them from scratch, attempting to import only the XML file but the same problem.
can you help please
check the link bellow :
https://drive.google.com/drive/folders/1zStcoFaP7LCoW1O01gH9yeHQGu43H9QJ?usp=sharing
Hello,
Please let me know what theme version you have.
Please update the theme to the latest version 12.6.4.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Thank you!
I have a newspaper theme, have been using for a few years for my website with no issue until sometime in January. Initially the main site was down for a day or so. While the display on the desktop has no issue now, a malware is acting on a mobile device. Anytime anyone visits the website from any mobile device, the redirect hacking malware becomes active. I checked this issue with my hosting company and I even hired a professional to work on. Both are pointing out it’s related to td composer. My jetpack scan results also indicates td composer as a threat. In fact, once I deactivate td composer plugin, the issue is resolved (no more redirect on mobile) but the landing page gets broken of course. My hosting company suggested that I should consult with the the theme developer. I don’t know what to do. Would you please help me? https://eyeonsligocreek.com/
Hello,
1. When the mobile theme plugin is used the pages content needs to be set using the mobile editor at the bottom of the page and this should be created using only elements from the mobile editor and not code from builders. If you want to use the responsive version, just disable the mobile theme plugin.
2. This problem seems to be caused by a malware – https://sitecheck.sucuri.net/results/https/marocafrika.org
– Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins;
– Delete the weird/unknown themes;
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)
– Check the live css tool, and make sure is working – https://i.imgur.com/xaXIEJO.png (set a css there and click on save)
example css:
.txt{
color: red;
}
Thank you!
Hello,
Please check this topic https://support.google.com/webmasters/thread/187593889/google-has-detected-harmful-content-on-some-of-your-site%E2%80%99s-pages?hl=en
Also, please scan the website for malware. You can use Wordfence.
Thank you!
Hello @Yigi!
Follow this guide to clean your WordPress and theme of malware: https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
After that, you can update the theme to the latest update.
For every update, we always recommend the following:
-> First of all, please make sure you have a backup.
-> Please deactivate all the non-tested plugins with our theme before updating.
-> Update WordPress, PHP, the theme, and plugins to the latest version: https://forum.tagdiv.com/how-to-update-the-theme-2/.
-> Check all these requirements for the theme: https://forum.tagdiv.com/requirements-for-newspaper/
Thank you!
After updating the globalenergy.mx site and the globalindustries.mx site, they presented malware that redirected the site to sales pages, most of the time if accessed from a mobile…
I managed to clean the globalindustries.mx site and it appears safely in sucri but it keeps redirecting me on mobile devices https://sitecheck.sucuri.net/results/globalindustries.mx
However, I updated the one from globalenergy.mx yesterday and it automatically appears as a risky site https://sitecheck.sucuri.net/results/globalenergy.mx
please help, me
I’m facing the same issue. A sudden spike in traffic due to malware has happened. The site is showing 525 and 500 errors. Hosting people are helpless and tried every way possible they are asking to raise issues in the forum. The complete issue is due to tagdiv plugins.
If someone has figured the way out kindly help me with this it’s been a week and I’m frustrated.