tagDiv Composer 5.4.4. unauthenticated user enumeration & AJAX vulnerability
Our site (running tagDiv Composer 5.4.4) was hit (STILL IS) with over 160,000 requests in less than 24 hours.
The attacker used the admin-ajax.php endpoint with Newspaper theme actions to trigger password reset triggers for the username teryaljw.teryaljw.
The bot is sending POST requests to: admin-ajax.php?td_theme_name=Newspaper&v=12.7.5
Even with “Anyone can register” set to OFF, the theme’s AJAX handler for user functions allows unauthenticated triggers of the WordPress wp_mail function via lostpassword_post. This allows the site to be used as a “spam relay” and causes massive server load.
In comparison, standard WordPress core blocks these attempts at the login screen while the Newspaper AJAX handler is bypassing these core protections.
Please implement Nonce Validation and Unauthenticated Request Filtering for all td_ajax_ account functions.
Hi,
Could you please share a link to your website?
Also, are you using the tagDiv Opt-in Builder plugin? If registration is not required on your site, please make sure the “Enable user registration” option is disabled https://prnt.sc/OMd_j0Ih11cl
Additionally, I recommend using tools like Wordfence and Cloudflare to help protect your site and prevent bots from accessing it.
Also, make sure that teh theme panel options are disabled – https://prnt.sc/DELlr2jMPO5e
Appreciate the advice, we have both, Wordfence and Cloudflare premium running but I was not asking about 3rd party tools but when are you going to implement Nonce Validation and Unauthenticated Request Filtering for all td_ajax_ account functions. It’s been years and several attacks that we’ve gone through – hacked twice already. Please fix it.

Also, we don’t use tagDiv Opt-in Builder plugin and Enable user registration” option is disabled.

the website is https://thevou.com
Hi,
I just checked your website, and it appears that you still have the signing on mobile on some pages and articles, so this is the problem (most likely, those are not even protected with reCAPTCHA https://prnt.sc/dK_CRlHv1fuH since you believe it is disabled on the site https://i.imgur.com/Y1oqLsJ.png – https://prnt.sc/A39SBfzgOQcf – https://prnt.sc/7V6Yyr4LLNxr). It is possible that you disabled the theme panel options recently, if so, please clear all cache and purchase the CDN.
Thank you!
They are all protected, can give you full access to the backend for you to see. Also, what do you mean by “purchase the CDN”. Finally why do you avoid the question: when are you going to implement Nonce Validation and Unauthenticated Request Filtering for all td_ajax_ account functions. It’s been years and several attacks that we’ve gone through – hacked twice already. Why don’t you fix it?
Hi,
Whenever a potential vulnerability is reported, we forward it to our developers for review. They investigate each case, and if it is confirmed to be a theme-related issue, it is addressed and fixed in a future update.
I have also reported this to our developers, and they will review it.
Hi,
As far as I know all known vulnerabilities have been fixed for the composer -> https://patchstack.com/database/wordpress/plugin/td-composer/vulnerabilities
In the last update there were fixes for the composer, cloud library, opt-in builder -> https://tagdiv.com/newspaper-changelog/ I don’t think there are more at this time. Please update the theme.
Thank you!




