Since yesterday, 16/11/2025, my site has been hacked.
My site is a blog with 14,482 articles and 14 page.
With the help of Wordfence, I have managed to locate all the malicious files and delete or replace them with new ones. The only thing I still cannot address is the tagDiv Cloud Library plugin. Can you help me with this? I have deleted all the files of the Newspaper theme and reinstalled them from scratch, as well as all the WordPress files and the other plugins.
It is very important for me to solve this problem quickly, because the site has very high traffic.
link: https://exostis.gr/wp-content/uploads/2025/11/tagDiv-Cloud-Library.jpg
After scab with Wordfence and the same from malcare
Plugin Name: tagDiv Cloud Library
Current Plugin Version: 3.9.2 | built on 22.10.2025 10:59
Details: To protect your site from this vulnerability, the safest option is to deactivate and completely remove “tagDiv Cloud Library” until a patched version is available. Get more information.(opens in new tab)
Vulnerability Information: https://www.wordfence.com/threat-intel/vulnerabilities/id/f97414f7-3544-4ecf-908a-a0215e322e68?source=plugin(opens in new tab)
Vulnerability Severity: 6.4/10.0 (Medium)
Hi,
I’m sorry to hear that you had problems with your site and it was hacked? How did you manage to get it back?
Regarding the vulnerability message in Wordfence, this is being misinterpreted. This has been fixed in 3.9.2, and only versions under 3.9.2 are affected – https://i.imgur.com/IIABdpb.png. We already contacted the Wordfence authors related to this.
Thank you for your understanding!
I purchased the Sucuri Security Platform Basic today (18/11/2025) for $229.00 per year, and it is reporting that the tagDiv Cloud Library has issues, as are the free versions of MalCare and Wordfence. All security-related plugins indicate that the tagDiv Cloud Library has a problem. As a result, my website is not functioning correctly. What else can I do? Also, users visiting the site are receiving warnings from their antivirus software stating that the site has an issue.
The website is hosted on a server by the company called Hetzner. Even from there (Hetzner), they are reporting that the website contains malware.
To which email should I send you the login details?