Security: Unpatched Vulnerability: Any Updates

Posted in: Newspaper
Post count: 59

This high severity vulnerability to still being reported with recommendation to delete the essential plug.
Are there any updates on this?

tagDiv Composer
PLUGIN
tagDiv Composer
PLUGIN SLUG
td-composer
VULNERABILITY
Cross Site Request Forgery (CSRF)
PATCHED IN VERSION
No Fix
SEVERITY SCORE
High
CVE
2023-39166
The vulnerability has not been patched. You should deactivate the plugin.

Post count: 27744

Hello,

Please let me know what version of the theme you have. If you don’t have the latest version of the theme 12.5, then please update it.
My recommendation is that before updating the theme to make a full backup for the database and current website, disbale the extra plugins during the update process, after that update the theme manually – https://forum.tagdiv.com/how-to-update-the-theme-2/ (after the theme update, make sure that the needed plugins are installed, like tagDiv Composer, maybe tagDiv Standard Pack and tagDiv Cloud Library).
In the worst cases, the settings in the theme panel may be lost (there have been isolated cases), in these cases, after the theme plugins that were previously used are activated, you will have to use a backup for the theme panel -> https://forum.tagdiv.com/import-export-theme-settings/

Thank you!

Post count: 59

12.5 with all the all the latest updates.

I-Themes security reports are being emailed to all their users reporting this as high severity vulnerability and advising to deactivate this essential plug-in.

As of Aug 2, it’s being reporting it as unpatched.

Post count: 1

Hello and welcome,
this is my first post on the forum. I have the latest version of the Newspaper theme 12.5) and at the same time in the Plesk panel a message about the threat is displayed, the details of which are pasted below. When can we expect the creators of tagDiv to fix this situation?

“Truoc Phan discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress tagDiv Composer Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has not been known to be fixed yet.”

Cheers
Piotr

Post count: 27744
Post count: 59

Thank you for the clarification

Viewing 6 posts - 1 through 6 (of 6 total)
The forum ‘Newspaper’ is closed to new topics and replies.