Hello, for your information there is a Vulnerability in the tagDiv Composer plugin
CSRF to XSS vulnerability discovered by Truoc Phan (Patchstack Alliance) in WordPress Plugin tagDiv Compose

https://patchstack.com/database/vulnerability/td-composer/wordpress-tagdiv-composer-plugin-4-1-csrf-to-xss-vulnerability?_a_id=110
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/td-composer/tagdiv-composer-41-cross-site-request-forgery-to-cross-site-scripting
could you correct ?
Could we please have an update on this issue pls? We recently discovered our websites were hacked. Trying to figure out what is causing it and narrowed it down to plugin vulnerabilities in TagDiv composer. I find nothing from tagDiv responding on this issue. Newspaper theme is the core of one of our websites. I would hate to have to switch to something else but if TagDiv does not get ahead of this issue, we may have to.
Please advise what’s happening.
-
This reply was modified 2 years by
sparky263.
Hello, it is my server panel (plesk) which informs me of the vulnerability, I might as well tell you that it is never wrong. As a result, the module of my panel calls me by email, but also by notification in the panel to tell me that the vulnerability is still present and not corrected to date. You need an update with the security prerequisites, nothing else.
For those posting that an update is needed; it’s generally a good idea to indicate which version *you* are using, otherwise tech support cannot provide a useful reply without needless back and forth to determine if you actually are vulnerable or just need to update your old plugin to new one.
( I don’t work here; just loooooooong time customer. )
Hello, if I talk about vulnerability, it’s necessarily because I’m on the latest version of the theme! after once again where you tell me that you are working on the theme, there is no point in responding then? Especially for mentioning me every time (I don’t work here.).
Does that suit you? or do you want other information?
https://snipboard.io/xseATz.jpg
-
This reply was modified 2 years by
boutiquepcland.
We have or are still reinstalling everything, with a fresh install of the latest version of TDC (4.8) on our NP themed site, and isolated the new install. Hopefully that will solve the problem. Sadly we did not discover the vulnerability soon enough, but hopefully with this fresh install we will have fixed the problem. We will have to be more vigilant in future.
Hello,
@boutiquepcland Please make sure you have the latest version of the theme, and that you have cleaned the files of malware.
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
@sparky263 Have you investigated and cleaned all the files to ensure there is no strange injected code?
Could you provide more details on what specific vulnerability you’re referring to?
Thank you!
Hi,
Did you check the wordpress files? Please do the following steps:
– Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins;
– Delete the weird/unknown themes;
– Clean unfamiliar Theme Panel injected code (example – https://i.imgur.com/4q70kCv.png);
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)
@Anamaria Hello, thank you for rereading my first post!

Hi,
Did you follow the above steps https://i.imgur.com/AWvh3Gz.png? Normally, if you clean the files and have the latest version of the theme, there should be no issue with WordPress now.
Thank you!
Hi,
This was resolved. I don’t know what issue you’re referring to, as those problems have been resolved https://i.imgur.com/wXStynl.png. Please check the changelog of the theme https://tagdiv.com/newspaper/
Thank you!
Hello, I’m going to see about changing the theme so, on the wordfence site this is not corrected https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/td-composer/tagdiv-composer-41-cross-site-request-forgery-to-cross-site-scripting. But OK !!!



