Hello,
We used newspaper 6.6.4 in the theme.
There is a security gap, how can we close it.
You can find detailed information below.
Cross-site Scripting
URL: https: //domain.com/wp-admin/admin-ajax.php? Td_theme_n Newspaper & v = up = 6.6.4
Parameter Name td_block_id
Parameter Type POST
Attack Pattern >
URL: https: //domain.com/wp-admin/admin-ajax.php? Td_theme_n Newspaper & v = up = 6.6.4
Parameter Name td_string
Parameter Type POST
Attack Pattern ((‘ > ‘))
URL: https: //domain.com/wp-admin/admin-ajax.php? Td_theme_n Newspaper & v = up = 6.6.4
Parameter Name: loopState%5BsidebarPosition%5D
Parameter Type: POST
Attack Pattern: (( ‘”–></style></scRipt><scRipt>netsparker(0x002796)</scRipt> “” ))
URL: https: //domain.com/wp-admin/admin-ajax.php? Td_theme_n Newspaper & v = up = 6.6.4
Parameter Name: loopState%5BmoduleId%5D
Parameter Type: POST
Attack Pattern: ((‘ > ‘))
Classification
PCI 3.1 6.5.7
OWASP 2013 A3
CWE 79
CAPEC 19
WASC 8
Thank you for your support.
Best Regards
-
This topic was modified 9 years by
bymorpheus.
-
This topic was modified 9 years by
bymorpheus.
-
This topic was modified 9 years by
bymorpheus.
Hi,
Please provide more details about this, I don’t understand exactly what is the security gap and how have you come to this conclusion. There are security plugins that you can use if you think your website is vulnerable. And also make sure you have the latest version of WordPress and you should update your theme as well and all the plugins that are bundled with the theme. Here is a guide with detailed steps to take if you decide to update
– https://forum.tagdiv.com/how-to-update-the-theme-2/
Thanks
Hi,
@Chris, WordPress versiyon 4.7.5 last version.
@Simion, What kind of detail do you want?
Details are available in my content.And references..
I already have a plugin, wpmudev defender.
Security software NetSparker was used and scanned.
https: //domain.com/wp-admin/admin-ajax.php? Td_theme_n Newspaper & v = up = 6.6.4
Td_string and more parameter accept post injection java script. (XSS attack)
P.S: Sorry my english is bad.
Thanks a Lot.
is that possible that the theme has infected from malvirus;;;; i have the the np6 and i have problem 3 days ago with fake users as administartors im my site http://www.mikrasiatis.gr
Well, theme has no XSS on any of our sites … and we are PCI-DSS certified, own our own box, blah blah.
Usually with this kind of weirdo thing, it’s advisable to reinstall the theme and plugins, and possibly clean install of WordPress. Or, it’s a ‘false positive’ from the plugin used to scan, simply because it doesn’t know the theme is accessing the WP ajax framework to “load more” content as query. Duh.
( I don’t work here. )