
WP Toolkit is reporting a high risk security vulnerability in TagDiv Composer on my website since 03.04.2025 throught Patchstack and Wordfence.
Current version is still on 5.2 on my current newspaper theme. Is this issue going to be addressed soon?

There is also a medium risk vulnerability report realted to Cross-Site Scripting.
Thanks in advance for the feedback.
-
This topic was modified 1 year by
ruilavrador.
-
This topic was modified 1 year by
ruilavrador.
Hi,
Please make a full backup of your website and update the theme to the latest version, Newspaper v21.7.1 – https://i.imgur.com/qoKwDsn.png Composer version Version 5.4.1
Thank you!
Hy Calin, thanks for the reply. Current version of my websites theme Newspaper is 12.6.8., shouldn’t the update show up on the theme panel as usual? Thank you!
Hi,
Yes, the theme update should be displayed in the Neaspaper theme in the update tabs, click on check for updates.
Also, before the update, make sure you’ll have a full backup. https://forum.tagdiv.com/how-to-update-the-theme-2/
Thank you!
Hi,
You need to click for check for updates – https://i.imgur.com/BkmLC6i.png
Thank you!
Hi Calin,
i already did, several times. There is some kind of connection issue that is not retrieving the themes latest update.
Please do a test using only tagDiv plugins.
Alternatively, the theme can be updated manually https://forum.tagdiv.com/how-to-update-the-theme-2/ – https://i.imgur.com/zh3je61.png
Hi Calin, after testing a manual update of the theme in a cloned stagging site, all the depending plugins where automaticly avaliable for update. Used the same method on the live site. Problem is now solved. Thanks.
Regards
Rui
