Td-composer security issue?

Posted in: Newspaper
Post count: 4

I’m running newspaper version (9.7.3) I’m getting this security alert from VaultPress
newspaper __td_deploy_version__
The theme newspaper (version 9.2.2) has a publicly known vulnerability. It is recommended to deactivate and remove this theme until a new version is released.

Can you update that file to include a proper version number. I’va also had an issue with Cloudflare, where my site went down and the only way to get it back up without running Cloudflare’s “under attack mode” was to disable the td-composer plugin.

I had to reload WordPress and the newspaper theme to get it to work with composer again. Now I’m getting the VaultPress alert, which I assume I can ignore.

Post count: 20688

Hi,

The latest theme version has no know vulnerability, when there were any in previous versions they were fixed as quickly as possible, in updates. From what I know there weren’t any similar reports after he release of 9.7.3.

Cloudflare’s under attack mode should be used in case of attacks, but this would not be related to out composer plugin. Maybe there really was an attack on the website, you could check logs if there are any, or scan the website, database etc. Or maybe the website went down because of a different issue, you could check server logs as well.

Thanks

Post count: 37

Hi, at 9.7.3 – still got this alert from vaultpress

Vulnerable WordPress Themes or Plugins

You are using outdated WordPress extensions with publicly known security issues. We recommend that you upgrade to the latest release. If you are no longer using these extensions, please delete them.

newspaper __td_deploy_version__
The theme newspaper (version 9.2.2) has a publicly known vulnerability. It is recommended deactivate and remove this theme until a new version is released.

Post count: 20688

Hi,

The message refers to an older theme version, if you updated to the latest version, why would it keep displaying that notification is beyond me. In fact in version 9.2.2 a security issue was fixed – http://prntscr.com/nycxyx
Maybe it doesn’t detect that you have updated the theme.

Post count: 4

Hi Simon, my theme is the latest 9.7.3. The real problem is that in wp-content/plugins/td-composer/style.css, I see this:


/*
Theme Name: Newspaper
Theme URI: http://tagdiv.com
Description: Premium WordPress template, clean and easy to use.
Version: __td_deploy_version__
Author: tagDiv
Author URI: http://themeforest.net/user/tagDiv/portfolio

Looks like __td_deploy_version__ didn’t get replaced by the actual version information?

Thanks,
Alex

Post count: 20688

I will pass this along to the developer team, maybe that was overlooked or maybe that is how it is supposed to be. If it has to be different it will be changed. Thank you for mentioning it.

Post count: 7

I’m having the exact issue with Newspaper 9.7.3 and VaultPress. This is the description

4:50pm, Fri, June 14
Detected the signature Vulnerable.WP.Extension on ./wp-content/plugins/td-composer/style.css.

I had to take it down.

David

Viewing 7 posts - 1 through 7 (of 7 total)
The forum ‘Newspaper’ is closed to new topics and replies.