tagDiv Composer, redirects to phishing sites

Posted in: Newsmag
Post count: 10

Hi,

I have big troubles with this site:

revistaprogreso.com.mx

seems to be hacked or something, it redirects for no reason to phising sites. I found this:

https://wpscan.com/vulnerability/993a95d2-6fce-48de-ae17-06ce2db829ef

seems to be the tag div composer plug in, because I deactivate and stops doing the redirection.

Could you help me please?

Post count: 35449

Hello,
If you notice that the site redirects to other sites, it may be because of injected malware. We recommend you follow the steps below:
– Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins;
– Delete the weird/unknown themes;
– Clean unfamiliar Theme Panel injected code (example – https://i.imgur.com/4q70kCv.png);
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)
– Update the theme to the latest version, Newspaper v5.2.3
If you have gone through the steps above and are still facing issues, don’t hesitate to contact us via email at contact@tagdiv.com. We’ll be ready to help you as soon as possible.

Thank you!

Post count: 10

Hi there,

I found that code on custom Java. Also change the admin password.
What else do I need to do to prevent this to happen again?

Thanks a lot for the help

Post count: 35449

Hi Carlos Bello,
Did you also check WordPress? Do you have extra files/directories that you do not know about? Also, please check the index.php if do not have an extra code.
After that be sure that you have the last theme version Newsmag v5.2.3, this version should block that code to be set again in the theme panel.
Thank you!

Viewing 4 posts - 1 through 4 (of 4 total)
You must be logged in to reply to this topic.