Detected vulnerabilities with TagDiv plugin

Posted in: Newspaper
Post count: 14

Hey, my WP anti-malware software has detected vulnerabilities ved tagDiv Composer (3.4 | built on 12.05.2022 9:11), which was a part of my Newspaper theme. What should I do now? i can’t seem to update it as it’s the latest version…

Post count: 27744

Hello,

This problem was solved in Newsapepr v12.1 -> https://wpscan.com/vulnerability/993a95d2-6fce-48de-ae17-06ce2db829ef, but as certain security plugins detect plugin version < 3.5, the problem was in 3.4. To solve the problem with <3.5 we changed the version to 3.6, all you have to do is delete tagDiv Composer and reinstall it from Newspaper > Plugins.

Thank you!

Post count: 14

is there somewhere an instruction on how to update from 11 to 12?

Post count: 27744

Hi,

If you want to update the theme, you should download the latest version of it from Theme Forest account and download it.
Please make a full backup to all files and database => https://www.youtube.com/watch?v=LAJXrSI-dDA
Here you can find information about the changes that have occurred in each update over time https://tagdiv.com/newspaper/
I recommend that you update the theme manually https://forum.tagdiv.com/how-to-update-the-theme-2/ via FTP/cPanel/File Manager, also if possible disable extra plugins during the theme update to avoid any problems that may arise and make sure that you have activated the tagDiv Standard pack plugin to keep the website’s look. You can try to update the theme on a staging website.
After you update the theme, you need to update the theme plugins too.
In the worst cases, the settings in the theme panel may be lost (there have been isolated cases), in these cases, after the theme plugins that were previously used are activated, you will have to use a backup for the theme panel -> https://forum.tagdiv.com/import-export-theme-settings/

Thank you!

Post count: 14

Thanks, just updated.

Post count: 14

The issue still exists… My developer writes:

The issue is occurring as your theme is overwriting the option_name -> td_011 in the wp_options table whenever we remove the malware from your site. The option_value is being overwritten by the content ->Causing the site to break. I have attached a copy of how this row looks like infected with malware when we remove the code starting with ” s:2340:\”eval(String.fromCharCode ” the entire row gets replaced with the content I attached above.

—-

Can you take a look at what is overwriting this?

File: https://d.pr/f/MeY7iW

Post count: 27744

Hi,

We can take a look so, please contact us via email at contact@tagdiv.com and provide the wp-admin and cPanel login.

Thank you!

Post count: 14

I just sent the credentials. Thanks

Viewing 8 posts - 1 through 8 (of 8 total)
The forum ‘Newspaper’ is closed to new topics and replies.