jetpack alert about td-composer vulnerability

Posted in: Newspaper
Post count: 5

Hi!

This morning I received a security warning from Jetpack about a known vulnerability of td-composer:

Vulnerable Plugin: td-composer (version 4.0 | built on 06.04.2023 10:28)

If I try to solve with Jetpack it removes the plugin and the theme is not usable anymore. Can you give me more informations? Is it a false positive?

Post count: 21065

Hello @bigadv!

Please make sure you have the theme and the plugins up to date.
Please execute these steps:
1. deactivate TagDiv Composer
2. uninstall (delete) TagDiv Composer
3. clear cache (if a cache plugin is present).
4. install TagDiv Composer
5. activate TagDiv Composer
6. clear cache (if a cache plugin is present).

Thank you!

Post count: 5

Hi Bettina,

I did it and now I’m performing a new security scan (by Jetpack), let’s see…

I think that the threat is related to this WPScan alert: https://wpscan.com/vulnerability/cada9be9-522a-4ce8-847d-c8fff2ddcc07

Post count: 21065

Hello @bigadv!

Our developers are investigating this case.

Thank you!

Post count: 5

Thank you!

I’ll wait for you feedback.

Post count: 6
Post count: 40

Same here (www.lochemsnieuws.nl). Can’t even access wp-admin.

Post count: 3

Yes – i have experienced same issue with jetpack notifying me about the td composer vulnerability. I have disabled my themes. Please update on this situation. Thank you!

Post count: 5

Hi Bettina,

Do you get any update about the vulnerability from your developers?

Post count: 40

I’d like to know how serious the tread is. Is it still save to use the newspaper theme?

Update would be nice. Thanks.

Post count: 21065

Hello guys!

Any fix will be added in the next update as of now.

Thank you!

Post count: 5

Same thing happening on my site and it’s very concerning. Any update?

Post count: 27744

Hi,

There is no issue because the security issue was added in the tagDiv Composer version 4.0 -> https://i.imgur.com/sF8iilF.png those from jetpack put a condition there lower than 4.0 and I think that’s why that alert appears. Please deactivate, delete and reinstall tagDiv Composer from Newspaper plugins => https://www.screencast.com/t/OrzLvR2j and clear all cache.

Thank you!

Post count: 6

insecure tagdiv theme

I got this alert via Jetpack scan as well and my site is loading slow past few days until I enabled Cloudflare Site Under Attack feature. Could this be an attack?

I think more Tagdiv users should know that the Newspaper theme is not secure. Based from my experience of using the theme past 6-months, the developer is more focused at placing unwanted ads in our WordPress dashboard to upsell their products. Clearly security of the theme is not a priority.

Post count: 27744

Did you make the steps provided above? As you can see here version 4.0 was fixed -> https://i.imgur.com/n7J93kq.png

Post count: 6

I am considering steps to replace the Newspaper theme itself. Do you want a progress update?

  • This reply was modified 3 years by scamboy.
Post count: 5

If it helps, this is the answer I got from the Jetpack team:

It appears that the root cause of this issue is the source code of the td-composer plugin, which is causing us to report an incorrect version number. Our team of developers is working on a fix to convert the version to the expected one and it should be fixed today.

For the time being, you can ignore the security threat associated with the td-composer plugin.

Post count: 6

thanks bigadv.

Viewing 18 posts - 1 through 18 (of 18 total)
The forum ‘Newspaper’ is closed to new topics and replies.