Hi Bettina
I understand that I shouldn’t deactivate it but iThemes Security is saying that it has an unpatched Cross Site Request Forgery and the risk is High.
They are saying that the risk of hacking is so high that we should not have websites that use the composer.
Please advise when this will be patched.
IThemes security is well respected and is telling all their clients, free and otherwise, not to use your product.
Please advise when this risk is being patched.
Thanks
Thank you, can you give an indication of when it will be fixed as soon as you can. I have seen an uptick of people trying to get into my sites since the warning came out.
I don’t believe we have long before we need to decide whether to stay with tag div. This warning may well stop tag div from acquiring new customers or retaining them.
Please help
Hello!
A solution for sending a screenshot/video is this:
Download, capture, and send: https://www.techsmith.com/jing-tool.html
After making the screenshot, you will have a link; paste it here.
Thank you!
On reflection a screenshot does not add anything – all the information is drawn from iThemes Security weekly report.
This is what they say about their report and what they have to say about this weeks:
Unpatched plugins and themes are the #1 reason WordPress websites get hacked. Our weekly WordPress Vulnerability Report covers recent WordPress plugin, theme, extension, and core vulnerabilities. Learn when to apply updates or replace software products that have unpatched vulnerabilities.
Since last week, 94 total vulnerabilities emerged in public disclosure. They may affect over 7 million WordPress sites. There are 56 plugin vulnerabilities with security patches, so run those updates!
Additionally, there are 35 plugin vulnerabilities and three theme vulnerabilities with no patch available yet.
If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories.
In that case, you should consider deactivation and removal in favor of alternative solutions.
This is the warning for this week on tagdiv composer:
PLUGIN
tagDiv Composer
PLUGIN SLUG
td-composer
VULNERABILITY
Cross Site Request Forgery (CSRF)
PATCHED IN VERSION
No Fix
SEVERITY SCORE
High
CVE
2023-39166
There is no patch available yet, deactivate.
This is a serious warning that goes out to all their customers. Please advise.
Thanks
Jude