Tagdiv Composer Plugin Vulnerability

Posted in: Newspaper
Post count: 9

Hi there,

My hosting company has raised concerns that the Tagdiv Composer plugin on my website (https://www.hotelspeak.com) is being exploited via a vulnerability and this is causing a very high load on their servers. Multiple connections are causing this – I’ve copy/pasted an example at the foot of this support ticket, for reference.

It appears as though this is a known issue and I see that it was supposed to have been resolved in version 5.4 (see https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/td-composer/tagdiv-composer-53-unauthenticated-arbitrary-php-object-instantiation) but I’m running 5.4 and apparently there are still issues.

Their solution is to disable the Tagdiv Composer plugin, but this is essential to the site and without it, the site doesn’t render correctly (just a lot of short codes).

Is this a known issue with the Tagdiv Composer plugin and will it be resolved in a future update? I really don’t want to have to a) move away from Newspaper (as it’s a great theme) or b) rebuild the site using a different page builder (assuming that’s even possibly within Newspaper).

Thanks

89.248.172.183 – – [13/May/2025:10:15:54 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”
89.248.172.183 – – [13/May/2025:10:15:53 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”
89.248.172.183 – – [13/May/2025:10:15:52 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”
89.248.172.183 – – [13/May/2025:10:15:54 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”
89.248.172.183 – – [13/May/2025:10:15:52 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”
89.248.172.183 – – [13/May/2025:10:15:53 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”
89.248.172.183 – – [13/May/2025:10:15:54 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”
89.248.172.183 – – [13/May/2025:10:15:55 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”
89.248.172.183 – – [13/May/2025:10:15:55 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”
89.248.172.183 – – [13/May/2025:10:15:56 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”
89.248.172.183 – – [13/May/2025:10:15:56 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”
89.248.172.183 – – [13/May/2025:10:15:57 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”
89.248.172.183 – – [13/May/2025:10:15:57 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”
89.248.172.183 – – [13/May/2025:10:15:56 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”
89.248.172.183 – – [13/May/2025:10:15:56 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”
89.248.172.183 – – [13/May/2025:10:15:57 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”
89.248.172.183 – – [13/May/2025:10:15:58 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”
89.248.172.183 – – [13/May/2025:10:15:58 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”
89.248.172.183 – – [13/May/2025:10:15:59 +0100] “POST /wp-json/tdw/save_css HTTP/1.1” 404 114 “-” “curl/7.68.0”

Post count: 35449

Hi,
Despite us fixing it at the time, attackers may try to exploit it, even if it’s useless to try. Are you perhaps using the Wordfence security plugin? It has an option that can be used to block specific requests – https://prnt.sc/1V-dHi7xTQXk Maybe similar plugins have such an option as well, in case you are using a different plugin. Or are you using cloudflare perhaps? If you do, you could block it there – https://prnt.sc/j97NJi77d5RO This kind of attack doesn’t usually last long, the requests should stop after some time.
Thank you!

Post count: 9

Thanks Calin.

So to confirm – Tagdiv has definitely resolved any potential exploits with the Tagdiv Composer plugin?

I’ve set up Wordfence now so hopefully that should help stop future attacks.

Sam

Post count: 35449

Hi Sam,
Yes, the vulnerabilities have been fixed. However, the bot can still make requests and potentially overload the server. While using Wordfence provides some protection, combining it with Cloudflare and properly configured WAF rules (https://prnt.sc/j97NJi77d5RO) is more effective. These rules will prevent bots from reaching the server in the first place.
Thank you!

Post count: 9

Thanks Calin – I really appreciate your help and will look into this further.

Viewing 5 posts - 1 through 5 (of 5 total)
The forum ‘Newspaper’ is closed to new topics and replies.