Same issue for me! have seen the same code (as @walshcreative reported above) appeared in custom JavaScript, and even after deleting and clean cache my site still cannot work
Same issue. Malware plugin was detected by Siteground (/public_html/wp-content/plugins/wp-clearlineee/wp-clearlineee.php in my case), and my site was taken offline. I checked the custom javascript code within the Newspaper theme and found the same code that others shared. I’ve deleted it for now.
@hmedia05 backup, delete folder wp-clearlineee in /public_html/wp-content/plugins, delete wp-clearlineee.zip in /public_html/wp-content/uploads/2022/11, delete any zip file in this folder, delete evrything in folder /public_html/wp-content/upgrade
take a look in /public_html is any new file, compare index.php
backup
update plugins, wordpress, theme
Change permission for /public_html/wp-content/upgrade to 444, when you need somthing to upgrade change to 755
Hi,
You can say it’s a “viral campaign” so many infections have been reported with different themes, not only with Newspaper or Newsmag.
I did more research and this malware is not from the theme, there are some viruses that are injected everywhere, in themes, plugins, and files.
Here are some reports and suggestions to fix the problem:
– https://wpxss.com/wp-admin/how-to-clean-trick-cofounderspecials-com-malware/
– https://guides.magefix.com/2022/09/cdn-weatherplllatform-com/
We will do more research and try to help as best we can!
Thank you!
Calin, you’re not giving us a solution since a couple of days that we have report the problem. Stop telling us it’s a viral campaign, people injected virus and malware… We know this happens because they use code vulnerabilities like the one you have here. I understand you don’t want to say it’s a theme problem, but I have talked with many developers with other themes, and they did not have the problem.
Someone is accessing tag div panel without a logged ip and then putting there malicious code. So then, your development team has to try to solve it asap. We have given you clear info about the process they use to do it, now it’s time for you to solve it.
Thanks Calin, I will update asap to new version. I have answered you in the other post saying that the code only works when injected manually, as we show you, and caches were cleaned after the injection. If caches not cleaned or code is not here in custom fields the site works fine (so it couldn’t be an infected file in the server because the malware should then ALWAYS work, I hope I’m explaining well).
-
This reply was modified 3 years by
loslunes.
Our developers made an update for users that have this problem, please check this topic – https://forum.tagdiv.com/topic/sql-injection-in-tagdiv-composer-again/
This continues to be an ongoing issue. Per this post your patch is not sufficient. This needs to be fixed as it’s a critical security threat impacting all of your customers, even those on the latest version.
This patch is not sufficient and this is very poor support:
https://forum.tagdiv.com/topic/sql-injection-in-tagdiv-composer-again/#post-458150
This issue is causing me to lose a ton of money. The support for this theme has always been fantastic.. Why has that changed?
I’m losing money, and a lot of time to fix it. And, by now, I’m not secure to updated the theme with this suppose “secure” new version. I’ve bought a licence of an anti-malware, and even the service said the “automatic cleanup of the site failed”. So, I had to contact the Malcare service for the “manual cleanup” of the malware, which is inside the Newspaper Theme. I don’t feel confident to updated, that’s it.
Hello, if the problem persists, after updating to v12.1.1 and the extra code and files have been checked and cleaned, there may be possible that some files are still infected. If you want, in this situation if you contact us by email at contact@tagdiv.com and provide wp-admin and FTP access, we will check the files and what else could be infected to make this problem reappear.
Thank you!