tagDiv Composer Plugin <= 5.4.1 is vulnerable to Cross Site Scripting

Posted in: Newspaper
Post count: 21

https://patchstack.com/database/wordpress/plugin/td-composer/vulnerability/wordpress-tagdiv-composer-plugin-5-4-1-cross-site-scripting-xss-vulnerability?_a_id=473

can you urgently advice how we can download 5.4.2 as in the recent update the 5.4.1 was only available?

Thanks

Post count: 35449

Hi,
You need to create a full backup for your website and update the theme to the latest version 12.7.2 and make sure that all theme plugins you are using now are updated.
https://forum.tagdiv.com/how-to-update-the-theme-2/
Thank you!

Post count: 21

Hi Calin, we did update to 12.7.2 but the plugin updated to 5.4.1 not 5.4.2. Now when we trying to update the system says we already are on the most updated version so it doesn’t update. Please let me know how we can get 5.4.2 for TagDiv Composer (the one with the patch)

Post count: 35449

Ohh, I see what you mean. I announced to the developers about this situation. It appears that the changes have been made, but they forgot to update the plugin version. We’ll do our best for next week to make a new update for this situation and the one with TOC.
Sorry for the inconvenience!
Thank you for your understanding!

Post count: 21

Ok, will we getting an automated update note when the fix has been published and a new release has been made or should we check somewhere else?

Post count: 35449

I think there will be an update on the theme, so you will be notified.

Post count: 21

Hi, is there an update on this issue? Thanks

Post count: 35449

Hi,
Yes, we just made a theme update, please go to Newspaper > updates and click on check for new versions. After that, it should display Newspaper v12.7.3 https://i.imgur.com/fcWbLGQ.png
Thank you!

Viewing 8 posts - 1 through 8 (of 8 total)
You must be logged in to reply to this topic.