Hi!
This morning I received a security warning from Jetpack about a known vulnerability of td-composer:
Vulnerable Plugin: td-composer (version 4.0 | built on 06.04.2023 10:28)
If I try to solve with Jetpack it removes the plugin and the theme is not usable anymore. Can you give me more informations? Is it a false positive?
Hello @bigadv!
Please make sure you have the theme and the plugins up to date.
Please execute these steps:
1. deactivate TagDiv Composer
2. uninstall (delete) TagDiv Composer
3. clear cache (if a cache plugin is present).
4. install TagDiv Composer
5. activate TagDiv Composer
6. clear cache (if a cache plugin is present).
Thank you!
Hi Bettina,
I did it and now I’m performing a new security scan (by Jetpack), let’s see…
I think that the threat is related to this WPScan alert: https://wpscan.com/vulnerability/cada9be9-522a-4ce8-847d-c8fff2ddcc07
Hi,
I have same alert on my site.
https://wpscan.com/vulnerability/cada9be9-522a-4ce8-847d-c8fff2ddcc07
Yes – i have experienced same issue with jetpack notifying me about the td composer vulnerability. I have disabled my themes. Please update on this situation. Thank you!
Same thing happening on my site and it’s very concerning. Any update?
Hi,
There is no issue because the security issue was added in the tagDiv Composer version 4.0 -> https://i.imgur.com/sF8iilF.png those from jetpack put a condition there lower than 4.0 and I think that’s why that alert appears. Please deactivate, delete and reinstall tagDiv Composer from Newspaper plugins => https://www.screencast.com/t/OrzLvR2j and clear all cache.
Thank you!

I got this alert via Jetpack scan as well and my site is loading slow past few days until I enabled Cloudflare Site Under Attack feature. Could this be an attack?
I think more Tagdiv users should know that the Newspaper theme is not secure. Based from my experience of using the theme past 6-months, the developer is more focused at placing unwanted ads in our WordPress dashboard to upsell their products. Clearly security of the theme is not a priority.
Did you make the steps provided above? As you can see here version 4.0 was fixed -> https://i.imgur.com/n7J93kq.png
If it helps, this is the answer I got from the Jetpack team:
It appears that the root cause of this issue is the source code of the td-composer plugin, which is causing us to report an incorrect version number. Our team of developers is working on a fix to convert the version to the expected one and it should be fixed today.
For the time being, you can ignore the security threat associated with the td-composer plugin.