td-composer triggering security threat warning from VaultPress

Posted in: Newspaper
Post count: 10

I received a security warning from VaultPress and they looked into it and said that td-composer is triggering a security warning due to an unsanitized PHP global variable being used to include or require other files. This poses a security risk for your site and should be addressed.

I recently installed the Gutenberg editor and TD-cloud – theme and all plug-ins are up-to-date.

What are my next steps? (in detail please, I am not an advanced user).

Post count: 22421

Hello,

There is no extra step for you to take. I will pass this information on to the development team and they will check if there really is a security threat or not. it is not the first time certain scanning tools provided false positives with our theme. Please provide a precise log of the scan so we can investigate the issue.

Thank you!

Post count: 10

Here it is: require_once( $_GET[‘wp_path’] . ‘/wp-load.php’ );

Post count: 22421

Thank you. I will pass this information on and we will take a look into this matter.

Viewing 4 posts - 1 through 4 (of 4 total)
The forum ‘Newspaper’ is closed to new topics and replies.