- TutorialsFrom WPBakery to tagDiv Composer
- TutorialsDefault Block Settings Guide
- TutorialsHow to Update the WPBakery Page Builder plugin
Hi,
The latest version of the theme 12.6.1 is safe -> https://patchstack.com/database/vulnerability/td-composer/wordpress-tagdiv-composer-plugin-4-1-csrf-to-xss-vulnerability.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
I can offer an alternative recommendation if you prefer that we don’t inspect your theme files. You could consider downgrading the WordPress version using the WP Downgrade plugin, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Thank you!
WordPress tagDiv Composer Plugin < 4.4 | built on 05.10.2023 12:50 is vulnerable to Cross Site Request Forgery (CSRF)
please fix the issue and give the new update in newspaper td-composer plugin.
Hi All,
I’m facing error Parse error: syntax error, unexpected ‘array’ (T_ARRAY), expecting function (T_FUNCTION) or const (T_CONST) in /home/lsphuoc/domains/mydomain.com/public_html/wp-content/plugins/td-composer/legacy/common/wp_booster/td_resources_load.php on line 8
After trying to update TD Composer and TD Cloud Library plugin. Please guide me how to fix them? I was try to I’m using latest version of wordpress (6.3) and Newspaper (12.6.1)
Regards,
Andy
hostinger detected vulnerability in td-composer please update the td-composer plugin.
hello
i have create a new page and return this error
wp_booster error:
td_api_base::mark_used_on_page : a component with the ID: tdb_template_2581 is not set.
/home/maroussiotika/public_html/wp-content/plugins/td-composer/legacy/common/wp_booster/td_api.php
can help me how fix ?
thanks
Hi I read on WordPress Pages, below selected Latest Posts Page: “TD Composer is disabled on Posts Page”.
Can’t I use TD Composer for this page? How to do that?
And I have another question: for pages where TD Composer is disabled or there is no template, I see classic editor page does not show classic sidebar widgets: why are classic sidebars not showing? Are they disabled by the theme?
Thank you.
Hello,
The changes should be done on those files:
– wp-content/plugins/td-composer/legacy/common/wp_booster/td_util.php
line 794 https://i.imgur.com/OLiObCB.png
line 3353 https://i.imgur.com/1kGH5gM.png
– wp-content/plugins/td-composer/includes/tdc_util.php
line 466 – https://i.imgur.com/psGbYmv.png
To get the theme plugins default code, just delete the plugins and reinstall them from Newsmag > plugin
I hope this will help you!
Hi,
The latest version of the theme 12.6.1 is safe -> https://patchstack.com/database/vulnerability/td-composer/wordpress-tagdiv-composer-plugin-4-1-csrf-to-xss-vulnerability.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
I can offer an alternative recommendation if you prefer that we don’t inspect your theme files. You could consider downgrading the WordPress version using the WP Downgrade plugin, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Thank you!
Hi,
The latest version of the theme 12.6.1 is safe -> https://patchstack.com/database/vulnerability/td-composer/wordpress-tagdiv-composer-plugin-4-1-csrf-to-xss-vulnerability.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
I can offer an alternative recommendation if you prefer that we don’t inspect your theme files. You could consider downgrading the WordPress version using the WP Downgrade plugin, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Thank you!
Greetings,
I’ve recently been alerted by my security plugin about a security vulnerability in TagDiv Composer, which is detailed in this link: https://patchstack.com/database/vulnerability/td-composer/wordpress-tagdiv-composer-plugin-4-1-csrf-to-xss-vulnerability?_a_id=350
Please inform me once the issue has been resolved.
please check the security issues showing in my hosting. and i click more showing below url
https://patchstack.com/database/vulnerability/td-composer/wordpress-tagdiv-composer-plugin-4-1-csrf-to-xss-vulnerability?_a_id=241
This is now what I see in my error log:
2023-11-02 10:34:35.776689 [NOTICE] [37430] [T0] [40.77.167.70:59063:HTTP2-1#APVH_sunny.broadcasteverywhere.biz:443] [STDERR] PHP Parse error: Unmatched ‘}’ in /home/sunnyfm/sunny.fm/wp-content/plugins/td-composer/legacy/common/wp_booster/td_util.php on line 1\n
2023-11-02 10:34:32.493920 [NOTICE] [37430] [T0] [216.129.144.82:49691-H3:25B203EBCDE48121-0#APVH_sunny.broadcasteverywhere.biz:443] [STDERR] PHP Parse error: Unmatched ‘}’ in /home/sunnyfm/sunny.fm/wp-content/plugins/td-composer/legacy/common/wp_booster/td_util.php on line 1\n
2023-11-02 10:34:31.329905 [NOTICE] [37429] [T0] [51.222.253.15:44924:HTTP2-1#APVH_sunny.broadcasteverywhere.biz:443] [STDERR] PHP Parse error: Unmatched ‘}’ in /home/sunnyfm/sunny.fm/wp-content/plugins/td-composer/legacy/common/wp_booster/td_util.php on line 1\n
2023-11-02 10:34:31.259475 [NOTICE] [37430] [T0] [216.244.66.238:48780#APVH_sunny.broadcasteverywhere.biz:443] [STDERR] PHP Parse error: Unmatched ‘}’ in /home/sunnyfm/sunny.fm/wp-content/plugins/td-composer/legacy/common/wp_booster/td_util.php on line 1\n
2023-11-02 10:34:29.967988 [NOTICE] [37430] [T0] [47.6.51.196:61295:HTTP2-29#APVH_sunny.broadcasteverywhere.biz:443] [STDERR] PHP Parse error: Unmatched ‘}’ in /home/sunnyfm/sunny.fm/wp-content/plugins/td-composer/legacy/common/wp_booster/td_util.php on line 1\n
Can you please be more specific about which file I’m supposed to replace that line of code in? There are multiple errors with “null” issues in separate paths. Are you saying to do that in all of them? Please define the paths I file path I should be replacing this code in.
A – home/sunnyfm/sunny.fm/wp-content/plugins/td-composer/includes/tdc_util.php on line 466\n
B – /home/sunnyfm/sunny.fm/wp-content/plugins/td-composer/legacy/common/wp_booster/td_util.php on line 794\n
C – /home/sunnyfm/sunny.fm/wp-content/plugins/td-composer/legacy/common/wp_booster/td_wp_booster_functions.php on line 3039\n
D – ALL
Looking forward to your reply, and this update you mentioned…
Email Us At: web@mediabrewup.com
Website: https://www.Sunny.fm
Some strange errors appeared in my error log that are all relevant to Tag Div Composer. I’ve taken a look at the lines it references in the first two errors, and I became confused on what was wrong. I wanted to come to you guys for an explanation and further examination of the errors listed below. Please explain to me how we might take steps forward to fix this. We have experienced some crashes of the website recently. Looking forward to your swift response.
Error Log:
2023-11-01 15:11:16.445819 [NOTICE] [27615] [T0] [185.191.171.2:7204#APVH_sunny.broadcasteverywhere.biz:443] [STDERR] PHP Warning: Attempt to read property “post_content” on null in /home/sunnyfm/sunny.fm/wp-content/plugins/td-composer/includes/tdc_util.php on line 466\n
2023-11-01 15:11:16.445729 [NOTICE] [27615] [T0] [185.191.171.2:7204#APVH_sunny.broadcasteverywhere.biz:443] [STDERR] PHP Warning: Attempt to read property “post_content” on null in /home/sunnyfm/sunny.fm/wp-content/plugins/td-composer/legacy/common/wp_booster/td_util.php on line 794\n
2023-11-01 15:10:55.314680 [NOTICE] [27615] [T0] [67.212.210.154:59412:HTTP2-1#APVH_sunny.broadcasteverywhere.biz:443] [STDERR] PHP Warning: Undefined array key “widget_id” in /home/sunnyfm/sunny.fm/wp-content/plugins/td-composer/legacy/common/wp_booster/td_wp_booster_functions.php on line 3039\n
2023-11-01 15:10:55.286719 [NOTICE] [27615] [T0] [67.212.210.154:59412:HTTP2-1#APVH_sunny.broadcasteverywhere.biz:443] [STDERR] PHP Warning: Undefined array key “widget_id” in /home/sunnyfm/sunny.fm/wp-content/plugins/td-composer/legacy/common/wp_booster/td_wp_booster_functions.php on line 3039\n
2023-11-01 15:10:31.952505 [INFO] [27614] [T0] [196.245.164.247:50657#APVH_sunny.broadcasteverywhere.biz:443] File not found [/home/sunnyfm/sunny.fm/406.shtml]
2023-11-01 15:10:31.436876 [INFO] [27615] [T0] [50.3.159.154:35193#APVH_sunny.broadcasteverywhere.biz:443] File not found [/home/sunnyfm/sunny.fm/406.shtml]
2023-11-01 15:10:30.421162 [INFO] [27614] [T0] [192.109.110.122:44852#APVH_sunny.broadcasteverywhere.biz:443] File not found [/home/sunnyfm/sunny.fm/406.shtml]
2023-11-01 15:10:29.832674 [INFO] [27614] [T0] [165.231.98.196:59178#APVH_sunny.broadcasteverywhere.biz:443] File not found [/home/sunnyfm/sunny.fm/406.shtml]
Dear Support,
how to resolve this below?
Howdy!
WordPress has a built-in feature that detects when a plugin or theme causes a fatal error on your site, and notifies you with this automated email.
In this case, WordPress caught an error with one of your plugins, tagDiv Composer.
First, visit your website (https://staging.nook.rs/) and check for any visible issues. Next, visit the page where the error was caught (https://staging.nook.rs/wp-admin/admin.php?page=td_theme_plugins) and check for any visible issues.
Please contact your host for assistance with investigating this issue further.
If your site appears broken and you can’t access your dashboard normally, WordPress now has a special “recovery mode”. This lets you safely login to your dashboard and investigate further.
To keep your site safe, this link will expire in 1 day. Don’t worry about that, though: a new link will be emailed to you if the error occurs again after it expires.
When seeking help with this issue, you may be asked for some of the following information:
WordPress version 6.3.2
Active theme: Newspaper (version 12.6.1)
Current plugin: tagDiv Composer (version 4.4 | built on 05.10.2023 12:50)
PHP version 8.1.25
Error Details
=============
An error of type E_ERROR was caused in line 49 of the file /var/www/clients/client1/web1/web/wp-content/plugins/td-composer/legacy/common/wp_booster/td_wp_booster_functions.php. Error message: Uncaught Error: Failed opening required ‘td_block.php’ (include_path=’.:/usr/share/php’) in /var/www/clients/client1/web1/web/wp-content/plugins/td-composer/legacy/common/wp_booster/td_wp_booster_functions.php:49
Stack trace:
#0 /var/www/clients/client1/web1/web/wp-content/plugins/td-composer/legacy/Newspaper/functions.php(21): require_once()
#1 /var/www/clients/client1/web1/web/wp-content/plugins/td-composer/td-composer.php(198): require_once(‘…’)
#2 /var/www/clients/client1/web1/web/wp-includes/class-wp-hook.php(310): {closure}()
#3 /var/www/clients/client1/web1/web/wp-includes/class-wp-hook.php(334): WP_Hook->apply_filters()
#4 /var/www/clients/client1/web1/web/wp-includes/plugin.php(517): WP_Hook->do_action()
#5 /var/www/clients/client1/web1/web/wp-content/themes/Newspaper/includes/wp-booster/tagdiv-wp-booster-functions.php(3): do_action()
#6 /var/www/clients/client1/web1/web/wp-content/themes/Newspaper/functions.php(19): require_once(‘…’)
#7 /var/www/clients/client1/web1/web/wp-settings.php(600): include(‘…’)
#8 /var/www/clients/client1/web1/web/wp-config.php(98): require_once(‘…’)
#9 /var/www/clients/client1/web1/web/wp-load.php(50): require_once(‘…’)
#10 /var/www/clients/client1/web1/web/wp-admin/admin.php(34): require_once(‘…’)
#11 {main}
thrown
I have done it by myself.
You need to fix the malware in the plugin, which appears on the all websites td composer
I have done the issues about the feature images/thumbs by myself.
You need to fix the malware from plugin td-composer
Check this screenshot also here https://app.screencast.com/LAvIrM0gzBfwp
Hostinger Security option saying that, this plugin td-composer has malware
Yes sure,
1st problem is the featured images are not showing on the homepage and articles on everywhere.
2nd Hostinger shows that this plugin td-composer has malware.
Please check the screenshot below
We are facing many issues with this plugin td-composer. please check and fix the problem with it as soon as possible.
Waiting for your quick reply
Hi,
The latest version of the theme is safe -> https://patchstack.com/database/vulnerability/td-composer/wordpress-tagdiv-composer-plugin-4-1-csrf-to-xss-vulnerability. You also need, to check the plugins and wordpress files.
Thank you!
I am using GoDaddy server; can you fix this for me what details do you want for fixing the issue.
the issue is in “wp-content/plugins/td-composer/includes/wpeditor.php” How can I fix it?
system status:
https://workdrive.zohoexternal.com/file/ezwox1e42a7b4a2334a76bedce5577423fe77
License:
https://workdrive.zohoexternal.com/file/ezwox0fc20ad8618c496a8a73d99e82601d5b
Network error:
https://workdrive.zohoexternal.com/file/ezwoxd1a2057a76f349aa85938926d86fc28c
I have all plugins deactivated and when I activate TagDiv Composer plugin I immediately get a ‘critical error’ message. Just before this happened I had enabled OpCode in the WHM so I am assuming it has something to do with that.
Please help! and Thank you!
Hello!
This option : https://prnt.sc/_oxUZmsKKwLl is available in the tagdiv Composer only for the flex blocks.
For the block 24, we have an option in the Newspaper -> Theme Panel -> Block Settings -> https://prnt.sc/kOIbK8V8ICTd
Thank you!
Yesterday, I noticed that my site login page was blank (the login/register form does not show) and went in to edit it with TD composer. I received this error:
wp_booster error:
td_api_base::mark_used_on_page : a component with the ID: td_resources_load is not set.
/home4/gcwqzxmy/public_html/wp-content/plugins/td-composer/legacy/common/wp_booster/td_api.php
I have tried disabling all plugins besides the TagDiv plugins to no avail. I have none of the required TagDiv plugins disabled. I have little to no experience programming for web, so I am at a loss as to what to try next.
Thanks in advance for your help.