td-composer Vulnerability issue

Posted in: Newspaper
Post count: 11

WordPress tagDiv Composer Plugin < 4.4 | built on 05.10.2023 12:50 is vulnerable to Cross Site Request Forgery (CSRF)
please fix the issue and give the new update in newspaper td-composer plugin.
patchstack.com detect td-composer is vulnerable
hostinger security detected vulnerablilty

Post count: 27744

Hi,

The latest version of the theme 12.6.1 is safe -> https://patchstack.com/database/vulnerability/td-composer/wordpress-tagdiv-composer-plugin-4-1-csrf-to-xss-vulnerability.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
I can offer an alternative recommendation if you prefer that we don’t inspect your theme files. You could consider downgrading the WordPress version using the WP Downgrade plugin, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.

Thank you!

Post count: 4

WordPress tagDiv Composer plugin < 4.4 – CSRF to XSS vulnerability

hi! i have these error. i did the last update to theme 12.6.1, but it still remained!

Post count: 27744

Hi,

Normally, this notice should not longer appear, as you can see here is verified and fixed -> https://i.imgur.com/iAzhkjQ.png

Thank you!

Post count: 11

I have installed “Newspaper 12.6.1” into my brand new refreshed website. My hosting provider is “hostinger.in”, but whenever td-composer is installed, my hosting security provider (powered by Patchstack) itself tells me that the plugin has a virus. Deactivate and delete the plugin.
There is no point in using this theme if you cannot remove this malware. We would prefer to choose other alternative themes.
So please let us know how we can get our refund.

We are also providing you the screen shot of our hosting dashboard, so please take it seriously. This is a question of security of our website

td-composer screenshort
https://photos.app.goo.gl/HJbPieW8gPCjzRpF7
td-composer screenshort

Post count: 27744

Hi,

We communicated with a member of the Patchstack team and we checked the plugin, that’s why it appears verified and fixed there, so please contact your host to check the plugin once more together if they want with those from Patchstack.
You can request a refund here: https://themeforest.net/refund_requests/new, this request will be analyzed if the terms of use of the theme have been respected.

Thank you!

Post count: 11

your taDiv td-composer is infected and vulnerable please recheck to your side for this plugin and release new update. I have given the link of screenshot below, please check it once and improve your product.
https://i.imgur.com/4Ko2xH0.png
https://i.imgur.com/2ygZ6Vf.png
https://i.imgur.com/QJHhIlo.png
https://i.imgur.com/7UHe6PX.png
https://i.imgur.com/ckVj5TW.png

Post count: 27744

Hi,

As you can see, the tagdiv Composer version is 4.4, and there is a version smaller than that is vulnerable, which means that you don’t have the latest version of the 12.6.1 theme, so please update, because the version 4.4 is verified -> https://i.imgur.com/sv01BCZ.png

Thank you!

Viewing 8 posts - 1 through 8 (of 8 total)
The forum ‘Newspaper’ is closed to new topics and replies.