In last weeks we have detected millions of bad requests to our WordPress installations that use the Newspaper template with Tagdiv Composer.
Our firewall is detecting this attacks however the server is experiencing excessively high traffic that is affecting its performance. There are millions of petitions like this one:
2024-02-02 12:31:20 Access 67.213.221.13 301 POST /wp-json/tdw/save_css HTTP/1.1
We would like to know when this security hole can be fixed.
Thank you.
? URGENT PLEASE!!
Is this related to https://arstechnica.com/security/2023/10/thousands-of-wordpress-sites-have-been-hacked-through-tagdiv-plugin-vulnerability/
https://www.techrbun.com/how-to-fix-tagdiv-newspaper-malicious-redirect-infection/
-
This reply was modified 2 years by
heathcliff.
Hello @heathcliff,
Please let me know what version of the theme you have.
Please make sure that you have the latest version of the theme 12.6.3
If an attacker wants to target this URL /wp-json/tdw/save_css they can do so. Even if the website uses a different theme, the attacker can still try that URL. We could add an option to be able to enable/disable the Live CSS, it will be considered. But for now in order to remove it this can only be done with a modification to the composer plugin. I think that all that removing it requires is to comment this line of code – https://prnt.sc/RtwvL5Nc4ikR -> https://prnt.sc/ymZmhdUfp57U But as I mentioned, the attacker can still try to access the URL.
Thank you!
Hey @anamaria,
Hmm you are right.
Thanks for the info. I am going to look into it and come back on this next week.
Thanks ?
