This high severity vulnerability to still being reported with recommendation to delete the essential plug.
Are there any updates on this?
tagDiv Composer
PLUGIN
tagDiv Composer
PLUGIN SLUG
td-composer
VULNERABILITY
Cross Site Request Forgery (CSRF)
PATCHED IN VERSION
No Fix
SEVERITY SCORE
High
CVE
2023-39166
The vulnerability has not been patched. You should deactivate the plugin.
Hello,
Please let me know what version of the theme you have. If you don’t have the latest version of the theme 12.5, then please update it.
My recommendation is that before updating the theme to make a full backup for the database and current website, disbale the extra plugins during the update process, after that update the theme manually – https://forum.tagdiv.com/how-to-update-the-theme-2/ (after the theme update, make sure that the needed plugins are installed, like tagDiv Composer, maybe tagDiv Standard Pack and tagDiv Cloud Library).
In the worst cases, the settings in the theme panel may be lost (there have been isolated cases), in these cases, after the theme plugins that were previously used are activated, you will have to use a backup for the theme panel -> https://forum.tagdiv.com/import-export-theme-settings/
Thank you!
Hello and welcome,
this is my first post on the forum. I have the latest version of the Newspaper theme 12.5) and at the same time in the Plesk panel a message about the threat is displayed, the details of which are pasted below. When can we expect the creators of tagDiv to fix this situation?
“Truoc Phan discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress tagDiv Composer Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has not been known to be fixed yet.”
Cheers
Piotr
Hi,
We fixed the issue https://tagdiv.com/newspaper/?utm_source=forum&utm_medium=menu&utm_campaign=forum_loggedin&utm_content=92178 -> https://i.imgur.com/il0AUG0.png by this
wasn’t updated https://patchstack.com/database/vulnerability/td-composer/wordpress-tagdiv-composer-plugin-4-1-csrf-to-xss-vulnerability
Thank you!