iTheme Security detects tagDiv files as a Vulnerable Software – how to fix it ?

Posted in: Newspaper
Post count: 364

My configuration:
WP = Current version: 6.2.2
Newspaper Theme version 12.5
iTheme Security Version 8.1.7

After every day site’s scan by Itheme Security add-on (https://wordpress.org/plugins/better-wp-security/)

I’ve got a Vulnerable Software message:

WarnKnown VulnerabilitiesHide Details

Wordpress tagDiv Cloud Library plugin < 2.7 – Unauthenticated Arbitrary User Metadata Update to Privilege Escalation vulnerability
WordPress tagDiv Composer plugin <= 4.1 – CSRF to XSS vulnerability
Wordpress tagDiv Cloud Library plugin, WordPress tagDiv Composer plugin
screenshot 1 – https://prnt.sc/zTPUrwCtPFIV
screenshot 2 – https://prnt.sc/EsgSzPVJusA_

Could you explain how to fix it ?

  • This topic was modified 3 years by kibiribi.
Post count: 27744

Hello,

If you have the latest version, then you can ignore them. I think those tools don’t detect right the plugins version, for example, the plugins versions in 12.5 for tagdiv Composer is 4.2, and tagDiv Cloud Library 2.8

Thank you!

Post count: 364

It’s ok but how to remove everyday alerts in this case?

Post count: 27744

Hi,

I hope the plugin and the website that mentions the problem to fix the version.

Thank you!

Viewing 4 posts - 1 through 4 (of 4 total)
The forum ‘Newspaper’ is closed to new topics and replies.