TagDiv Composer plugin vulnerabilities

Posted in: Newspaper
Post count: 30

Hello, for your information there is a Vulnerability in the tagDiv Composer plugin

CSRF to XSS vulnerability discovered by Truoc Phan (Patchstack Alliance) in WordPress Plugin tagDiv Compose

CVSS

https://patchstack.com/database/vulnerability/td-composer/wordpress-tagdiv-composer-plugin-4-1-csrf-to-xss-vulnerability?_a_id=110
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/td-composer/tagdiv-composer-41-cross-site-request-forgery-to-cross-site-scripting
could you correct ?

Post count: 9544

if you read the old page you link to:
SOLUTION: Update the WordPress tagDiv Composer plugin to the latest available version (at least 4.4).
( I don’t work here. )

Post count: 103

Could we please have an update on this issue pls? We recently discovered our websites were hacked. Trying to figure out what is causing it and narrowed it down to plugin vulnerabilities in TagDiv composer. I find nothing from tagDiv responding on this issue. Newspaper theme is the core of one of our websites. I would hate to have to switch to something else but if TagDiv does not get ahead of this issue, we may have to.
Please advise what’s happening.

  • This reply was modified 2 years by sparky263.
Post count: 30

Hello, it is my server panel (plesk) which informs me of the vulnerability, I might as well tell you that it is never wrong. As a result, the module of my panel calls me by email, but also by notification in the panel to tell me that the vulnerability is still present and not corrected to date. You need an update with the security prerequisites, nothing else.

Post count: 9544

For those posting that an update is needed; it’s generally a good idea to indicate which version *you* are using, otherwise tech support cannot provide a useful reply without needless back and forth to determine if you actually are vulnerable or just need to update your old plugin to new one.
( I don’t work here; just loooooooong time customer. )

Post count: 30

Hello, if I talk about vulnerability, it’s necessarily because I’m on the latest version of the theme! after once again where you tell me that you are working on the theme, there is no point in responding then? Especially for mentioning me every time (I don’t work here.).

Post count: 30

Does that suit you? or do you want other information?

https://snipboard.io/xseATz.jpg

Post count: 9544

sure if you cannot type in numbers in a form, screen cap works… my plesk/parallels system is not noting this issue…
you will hear from support on monday, im sure 🙂

Post count: 103

We have or are still reinstalling everything, with a fresh install of the latest version of TDC (4.8) on our NP themed site, and isolated the new install. Hopefully that will solve the problem. Sadly we did not discover the vulnerability soon enough, but hopefully with this fresh install we will have fixed the problem. We will have to be more vigilant in future.

  • This reply was modified 2 years by sparky263.
  • This reply was modified 2 years by sparky263.
Post count: 3

Well question remains what theme version *you* where using. We already know the outdated versions have security hacks

Post count: 27744

Hello,


@boutiquepcland
Please make sure you have the latest version of the theme, and that you have cleaned the files of malware.
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.


@sparky263
Have you investigated and cleaned all the files to ensure there is no strange injected code?

Could you provide more details on what specific vulnerability you’re referring to?

Thank you!

Post count: 30

Link already present, it seems to me? https://snipboard.io/xseATz.jpg

Post count: 27744

Hi,

Did you check the wordpress files? Please do the following steps:
– Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins;
– Delete the weird/unknown themes;
– Clean unfamiliar Theme Panel injected code (example – https://i.imgur.com/4q70kCv.png);
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)

Post count: 30

@Anamaria Hello, thank you for rereading my first post!

https://snipboard.io/uDMjIN.jpg

Post count: 27744

Hi,

Yes, there was a vulnerability, but it has been fixed a long time ago

Thank you!

Post count: 30

@Anamaria It still seems to be there unfortunately.

Post count: 30

WordPress tagDiv Composer plugin

Post count: 27744

Hi,

Did you follow the above steps https://i.imgur.com/AWvh3Gz.png? Normally, if you clean the files and have the latest version of the theme, there should be no issue with WordPress now.

Thank you!

Post count: 30
Post count: 30

https://snipboard.io/AbidCQ.jpg

Post count: 27744

Hi,

This was resolved. I don’t know what issue you’re referring to, as those problems have been resolved https://i.imgur.com/wXStynl.png. Please check the changelog of the theme https://tagdiv.com/newspaper/

Thank you!

Post count: 30

Hello, I’m going to see about changing the theme so, on the wordfence site this is not corrected https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/td-composer/tagdiv-composer-41-cross-site-request-forgery-to-cross-site-scripting. But OK !!!

Viewing 22 posts - 1 through 22 (of 22 total)
You must be logged in to reply to this topic.