1 vulnerability found by Jetpack Protect

Posted in: Newspaper
Post count: 44

Jetpack has found a vulnerability in the Newspaper tagDiv composer. Now we can’t peacefully sleep at night without thinking about being hacked. Here’s the message below:

tagDiv Composer (3.5 | built on 19.10.2022 13:12)

tagDiv Composer < 3.5 – Unauthenticated Account Takeover
What is the problem?
The plugin, required by the themes, does not properly implement the Facebook login feature, allowing unauthenticated attackers to log in as any user by just knowing their email address.

See more technical details of this vulnerability
How to fix it?
Update to tagDiv Composer 3.5

Post count: 27744

Hello,

This problem was solved in Newsapepr v12.1 -> https://wpscan.com/vulnerability/993a95d2-6fce-48de-ae17-06ce2db829ef, but as certain security plugins detect plugin version < 3.5, the problem was in 3.4. To solve the problem with <3.5 we changed the version to 3.6, all you have to do is delete tagDiv Composer and reinstall it from Newspaper > Plugins.

Thank you!

Post count: 44

Thanks, the issue has been resolved. You were really helpful

Viewing 3 posts - 1 through 3 (of 3 total)
You must be logged in to reply to this topic.