No search results were found in Documentation!
Url: medibulletin.com
When TagDiv composer is installed the website is redirected to some SPAM website. Therefore i just uninstall the pugin, now homepage is showing some codes, the site is not working properly.
Please provide comprehensive solution of the redirection issue.
Hello,
Please let me know what version of the theme you have on the websites.
Please update the theme to the latest version 12.6.5.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins;
– Delete the weird/unknown themes;
– Clean unfamiliar Theme Panel injected code (example – https://i.imgur.com/4q70kCv.png);
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)
Please block /wp-json/tdw/save_css
If an attacker wants to target this URL /wp-json/tdw/save_css they can do so. Even if the website uses a different theme, the attacker can still try that URL. We could add an option to be able to enable/disable the Live CSS, it will be considered. But for now in order to remove it this can only be done with a modification to the composer plugin. I think that all that removing it requires is to comment this line of code – https://prnt.sc/RtwvL5Nc4ikR -> https://prnt.sc/ymZmhdUfp57U But as I mentioned, the attacker can still try to access the URL.
Thank you!
Do a search on here for ‘malware’ to find the remediation steps for those who got infected via theme or other plugin vulnerability (since patched). I don’t work here.
Hello,
Unfortunately my theme SQL tables are hacked and constantly redirecting other add websites etc.
I need to clean these SQL DB tables and re-install the theme.
Could you please tell me what SQL tables are used? I can’t see any obvious ones in phpMyAdmin.
Best, Isa
Hello,
We recommend using PHP version 8.0 or 8.1; with version 8.3, certain issues may arise.
1. You need to download the latest version from Themeforest and perform the update manually. We recommend conducting the update on a staging website because there have been many changes from version 9.1 to 12.6.5. Additionally, the auto-update option was only added later in version 10.3.x.x.
2.No, you don’t need to purchase a new license, as updates are for a lifetime if the license is valid.
3. The license remains the same; only the theme version differs, so you can use the same license on the website where you currently have that older version.
4. Over time, vulnerabilities have been discovered and resolved through updates. You can find the changelog for each version here -> https://tagdiv.com/newspaper/
Unfortunately, the tagdiv Composer may be disabled due to malware, so certain plugin files may be targeted. However, this can only be seen in the error log file. I recommend that after updating the theme, WordPress, and PHP, you use Wordfence to scan the website and block access to /wp-json/tdw/save_css
If an attacker wants to target this URL /wp-json/tdw/save_css they can do so. Even if the website uses a different theme, the attacker can still try that URL. We could add an option to enable/disable the Live CSS, and it will be considered. But for now in order to remove it this can only be done with a modification to the composer plugin. I think that all that removing it requires is to comment this line of code – https://prnt.sc/RtwvL5Nc4ikR -> https://prnt.sc/ymZmhdUfp57U But as I mentioned, the attacker can still try to access the URL.
Thank you!
Hello,
You should download the latest version of it from the Theme Forest account and download it.
Also, please follow the steps above to identify and remove malware, even though you mentioned using Wordfence, I suggest using it after updating the theme and WordPress to check the files again.
Thank you!
Hello.
At the moment, the Newspaper theme version 9.1 is installed and used on my site. WordPress has been updated to version 6.4.4. Php version 7.4.33 is used on the hosting.
There are more and more problems with the old version, and in order not to deal with them, it would be nice to update the theme version. There is an opportunity to upgrade the php version on the hosting up to 8.3. WordPress will also be updated before updating the theme.
But I have a number of questions, as some points are unclear.
1) I bought the Newspaper version 9.1 theme 5-6 years ago or more. There is an activation key and it is applied to the theme on the site. But on the tabs of the theme settings, I do not see where it would be possible to update between versions or sub-versions from the administrative part of the theme. As shown in the tutorial on updating the theme. That is, I will most likely have to update the new version via Ftp. Tutorial I read how to do it.
2) To get the new version, will I have to pay for it in full, as a new separate product? That is, not as an update for an already purchased product at any discount or reduced cost, for example.
3) Will the activation key be new or will the old one remain, which is currently activated by the current version of the theme?
4) And I want to understand whether the update will solve the problems that currently exist with the theme and its plugins.
Currently, there is a vulnerability issue for new malware in older versions. Malware was encountered and something was partially defeated by making edits to the theme code, something was limited by banning the REST API for the site, since installing a clean WordPress and a clean theme did not bring results.
And periodically, the tagDiv Composer plugin is deactivated by itself. It occurs at different times of the day and with different frequency by day. I have not been able to detect dependence on anything.
Therefore, I would like to understand that updating to the latest version of the theme has fixes for these problems. At least a security solution against the current malware attack and infection mechanisms. And it will be very cool if the update also solves the problem of self-deactivation of the plugin. Otherwise, it greatly spoils the appearance of the site when the Composer plugin is disabled.
I hope for understanding and help in answering my questions.
As soon as everything becomes more or less clear, I will send the answers to my management so that they pay for the new version and we will receive the new version of the topic as soon as possible.
Hi,
Please use Wordfence to check for malware. You can let only the logo without a link.
Thank you!
Hi,
There is no malware as I have scanned it. It is only affecting when the tagdiv composer is active. The site is pretty new with no plugins from outside. The only thing that was installed after downloading was from Tagdiv. The other plugin is what I have built yesterday. But this has been the situation from the time I was building the site.
Hi,
I think that there is malware. Please try to use Wordfence to scan the website and check if there appears warnings.
Thank you!
Hello,
Upon a quick analysis, I noticed that you’re using an older version of the theme.
Please update the theme to the latest version 12.6.5.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins;
– Delete the weird/unknown themes;
– Clean unfamiliar Theme Panel injected code (example – https://i.imgur.com/4q70kCv.png);
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)
If you’re not sure how to do it, our custom work team can help you with both theme updates and malware file cleanup https://tagdiv.com/submit-a-request/
Thank you!
Hello,
I have the following problem: one of my sites with its Newspaper theme called http://www.imagenesyespecialistas.com has been presenting an issue for weeks where it only redirects to other advertising sites on the mobile version.
Before realizing that it was the TagDiv Composer, I used all the tools available to find the vulnerability. I debugged plugins one by one, but the problem persists.
I used Wordfence, Sucuri, Quttera Web Malware Scanner, and the tools provided by my hosting provider, but the problem still persists.
I consulted my hosting provider and this was their response:
“Hello,
We have been able to verify that the “td-composer” plugin is the cause of the problem.
You can disable the plugin and check again.
If the problem persists, please contact the corresponding plugin vendor.
Best regards,
Roshney P.
BanaHosting.com Inc.
Think Big, Think Bana!”
After receiving this message, I did the following:
I deleted the theme and reinstalled it, but the problem continues. I only installed the TagDiv Composer plugin after downloading it from https://themeforest.net/.
I would appreciate any help with this problem, as it would be very helpful for me and future individuals facing this issue. Thank you very much!
Hello,
Please do a test by renaming the theme using cpanel/ftp and check if the issue persists also, you can try to use a default theme. Maybe you have malware, and you need to reinstall the theme and wordpress.
Thank you!
Hi,
Please update the theme to the latest version 12.6.5.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins;
– Delete the weird/unknown themes;
– Clean unfamiliar Theme Panel injected code (example – https://i.imgur.com/4q70kCv.png);
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)
If you’re not sure how to do it, our custom work team can help you with both theme updates and malware file cleanup https://tagdiv.com/submit-a-request/
Thank you!
Hello!
Follow this guide to clean your WordPress and theme of malware: https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
After that, you can update the theme to the latest update.
For every update, we always recommend the following:
-> First of all, please make sure you have a backup.
-> Please deactivate all the non-tested plugins with our theme before updating.
-> Update WordPress, PHP, the theme, and plugins to the latest version: https://forum.tagdiv.com/how-to-update-the-theme-2/.
-> Check all these requirements for the theme: https://forum.tagdiv.com/requirements-for-newspaper/
Thank you!
Hi,
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Thank you!
My site URL: https://converseer.com
My website, URL above, has been up for over two years without viruses or malware but since I purchased Newspaper Theme from Theme Forest and started using it, my site visitors started complaining of viruses and malware.
I did a scan and found some issues with the TagDiv Composer (2) and TagDiv Cloud Library (4) – the only two plugins I have on my site.
First, I noticed users were being added to by site without my knowledge and when I remove the users, they will be readded again, most times, new ones, and it happens when I am off the site.
It kept happening until I had to remove the Opt-In Builder plugin, which I suspected was adding users without my knowledge.
Today, I got messages from my site users that my site has been compromised and my page views have dropped.
See screenshot:
1. https://paste.pics/a8a7d0e1284c50da74f01ea8871c4eb3
2. https://paste.pics/7b3df2dc4a5b1e8daf85af1f7f4e7179
See scan result: https://wpscan.com/scan/a532f789-482c-4607-b437-9047cb8c8fdd/
Please, I need help.
Hello,
@boutiquepcland Please make sure you have the latest version of the theme, and that you have cleaned the files of malware.
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
@sparky263 Have you investigated and cleaned all the files to ensure there is no strange injected code?
Could you provide more details on what specific vulnerability you’re referring to?
Thank you!
Hello,
I recommend updating the theme to the latest version, 12.6.5 to be updated and to don’t have malware.
If you want to update the theme, you should download the latest version of it from Theme Forest account and download it.
I recommend that you update the theme manually https://forum.tagdiv.com/how-to-update-the-theme-2/ via FTP/cPanel/File Manager, also if possible disable extra plugins during the theme update to avoid any problems that may arise and make sure that you have activated the tagDiv Standard pack plugin to keep the website’s look. You can try to update the theme on a staging website.
After you update the theme, you need to update the theme plugins too.
In the worst cases, the settings in the theme panel may be lost (there have been isolated cases), in these cases, after the theme plugins that were previously used are activated, you will have to use a backup for the theme panel -> https://forum.tagdiv.com/import-export-theme-settings/
Thank you!
Hello,
You can contact our custom work team here, and they can help you update the theme safely and clean the files for malware: https://tagdiv.com/premium-customization-services/. Only then can you work as expected on the website.
Thank you!
we tried reinstalling wordpress and activated 3 mentioned plugins but still i am facing an issue as it gets deactivated / not able to edit the post and updates as well
as advised, installed wordfence to protect and scan all malware and vulnerabilities. kindly advise the steps to install the updated theme and try to reactivate the theme.
we work very hard in the prayer website and dont want to lose our website.
kindly help me to get this sorted out once for all
Hello,
Please provide the link to your website.
I think that you have malware on the website. Please update the theme to the latest version 12.6.5.
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Thank you!
Hello,
You have malware on the website. Please update the theme to the latest version 12.6.5.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Thank you!
Weird solution, all indicates that your theme was vulnerable for this malware. I have two different sites, in different hosts and both got infected the same way.
Hi,
So, in order to no longer have malware, you need to update the theme. From what I see, you have 9.8, which is a very old version and is likely vulnerable to new technologies, which is why I suggested updating the theme and following all the steps above. If you’re not sure how to do it, our custom work team can help you with both theme updates and malware file cleanup https://tagdiv.com/submit-a-request/
Thank you!