Update Tag Div Composer and WP Bakery page builder plugin

Posted in: Newspaper
Post count: 2

Hello, I have Newspaper version 10.2 and my antivirus won’t let me go to the my website with the JS/Agent.RAN trojan warning.
I would like to update tag div composer and WP Bakery page builder plugin, but I would not change the Newspaper version. Please help how to do it, thanks

Post count: 21065

Hello @dubravko !

I would gladly recommend you to make a backup and update plugins and the theme via file transfer to the latest update: https://forum.tagdiv.com/how-to-update-the-theme-2/
First of all, please make sure you have a backup done and then you can update the theme and the TagDiv plugins also.
Please take a look for this advice before updating: https://forum.tagdiv.com/topic/action-required-please-read-how-to-update-to-the-newspaper-theme-v-10/
Also, please use only one builder and not both because they will be in a plugin conflict.
If you have some custom modifications in the theme files, then better save the code and replace it after every update.

You can contact our custom work team here: https://tagdiv.com/premium-customization-services/ and they will help you.

Thank you!

Post count: 1

Hey Dubravko,

i am struggling with the same problem @www.werne-plus.de.

Did you already solve the problem? How did you do it?

Post count: 2

Hello,
I have two questions:
In accordance with your recommendation, I downloaded the latest version of Newspaper, updated and updated plugins, but my antivirus still warns me about JS/Agent.RAN. I was recommended by ESET NORT 32 to look for the “iz.fromCharCode” string that is associated with a malicious JS script, but I honestly don’t know how to do that, so please help.

Furthermore, you recommended me to use only one builder because of plugin conflicts. WP BAKEY VISUAL COMPOSER is much more friendly to me, but if I turn off TAG DIV COMPOSER, I get a message that it is needed for TAGDIV MOBILE THEME and TAGDIV STANDARD PACK, and my page “falls apart”, becomes unreadable.

Thank you in advance for your help, Dubravko

Post count: 13

Hello,
for everyone with this problem, you have to:
disable newspaper theme and delete the folder. Disable td composer and all plugins related to newspaper theme. Delete all.

Go to wp-content/plugins and search wp-zexit or wp-swamp.. delete folders

we will Install a fresh wordpress.. backup your wp-content folder to not lose your uploaded files, etc… backup wp-config.php, and any other file you find important inside your site folder. We will erase the folder. Backup your database.

Delete all files inside your site folder.

Download WordPress from wordpress . org/latest.zip , unzip it in the site folder. Please note that it will create a wordpress/ folder, and you need to copy all files to your root folder

restore your wp-config.php and wp-content folder that you have backed up

Now you have to check if your database is compromised, probably it is

on your wordpress database, check on wp_users if it have an user that is not created by you, probably with the name “greeceman”. Using command line code is ‘select * from wp_users;’

Delete user.. if the Id of the hacker user is for example 19, then use ‘delete from wp_users where ID=19;’ if you are using command line. Please don’t ever use SQL commands without the where clause.

Check if there’s something on ‘td_live_css_local_storage’ using ‘select option_value from wp_options where option_name = ‘td_live_css_local_storage’;’, probably is full of obfuscated sh1t.

Clear with ‘UPDATE wp_options SET option_value = ” WHERE option_name = ‘td_live_css_local_storage’;’

Post count: 21065

Hello!


@Kpkna
Thank you for sharing a possible solution for this malware.

@dubravko
That plugin is deprecated and it is not used anymore in the latest update. Please check those screenshots to know how to shift from WPBakery to Composer: https://www.screencast.com/t/6xLVMmlsY ; https://www.screencast.com/t/zWHrRmK1LQC ; https://www.screencast.com/t/vuFdT9Stx ; https://www.screencast.com/t/DWbSf3qj ; https://www.screencast.com/t/QuHyGccTK71v

Thank you!

Post count: 15

Hi boss !!
DO Version: 12.6 fix the JS/Agent.RAW problem or still vulnerable?

  • This reply was modified 2 years by RAINA.
Post count: 21065

Hello @Raina!

Do you have the latest update of the theme, and have you tried the steps from above?
If the problem is still there, then contact us via email at contact@tagdiv.com and provide the following:
– admin url and credentials
– cpanel url and credentials
– a link to this topic in order to identify you
We will take a look and try to help you asap.

Thank you!

Post count: 15

I fixed the problem, but i want to know if you have fixed in the last update…
or we need to wait another update !

Post count: 21065

Hello @raina!

I’m glad that you solved your issue.
Unfortunately, we can’t delete your database if you have any compromised files.
In the next update, you won’t have any issues because the new versions of the theme are not compromised.
But if you do not solve the issues before the update, then of course the issue will persist there.

Thank you!

Post count: 25

Dear Bettina,
we have the same problems with the tag div composer. Did you solve the problem in the latest update, so that we can make a clear new installation and have a theme without vulnerable files? If yes please provide the version number without these known problems.
Thanks
Dennis

Post count: 21065

Hello Dennis!

Yes. If your website is not already hacked, then you can safely update the theme to the latest update(12.6).

Thank you!

Post count: 91

hi,
i have the problem with wp-zexit. My version is newspaper: 11.5.1

This the code of the malware inside in some page: https://prnt.sc/dr7LcY9fg5SR

How do I solve the problem? If you want I can provide you with the credentials. The issue is quite urgent

Post count: 21065

Hello @ersandrino !

You should delete the entire script: https://prnt.sc/KpaaEh1M3Hg9
Usually, there is more than one place. That’s why you should delete every hacked path.
Follow this guide to clean your WordPress and theme of malware: https://askwpgirl.com/10-steps-remove-malware-wordpress-site/

Thank you!

Post count: 29

I also have a problem with malware associated with TagDiv Composer
Avira antivirus flagged it (https://i.imgur.com/RUuzOPv.png). Apparently it makes a request to: “https://cdn.statisticscripts.com/stats/step.js”

My host identified it in Tagdiv Composer; they provided this picture (which btw means nothing to me): https://i.imgur.com/XvUnPSD.png
Sadly they do not offer help with removal

Anyway the first thing I did was to delete my old version of Newspaper and install the new v12, but sadly this broke my site, so I reverted back

Next I deleted tagdiv composer plugin, but was not able to install the new version with the old version of Newspaper that exists on my site. I found an old version of the plugin from 2018 saved locally on my hd and installed it. I thought for a while that this fixed the problem, but it came back.

I am reading and re-reading the posts above, but do not feel any closer to a solution. Any help would be appreciated.

Post count: 21065

Hello @kurdi !

You should delete those values from your database. We already discussed about this issue in this topic as well: https://forum.tagdiv.com/topic/wp-zexit-malware-and-newspaper-theme-problem-please-see/
There you will find the solution provided by mmorselli.

Thank you!

Post count: 29

Bettina link above seems to be broken

Post count: 21065

Hello @kurdi !

It’s not broken. Copy-paste manually the link in another tab.

Thank you!

Post count: 89

I have the same issue, and nobody can remove the malware, not even the Sucuri team. Where can I send you my credentials so you can have a look, please?

Post count: 22

Hi Tagdiv,

So what is the final solution here?

This is just a work around on how to identify where is the malware.

Did you already have a fix for the vulnerability? Even if we follow steps here – there’s always a tendency for the site to be hacked again unless you apply a fix to the plugin/theme.

Your response puts us in circles.
You reply the solution is in this link: https://forum.tagdiv.com/topic/wp-zexit-malware-and-newspaper-theme-problem-please-see/

Then that link points to this link: https://forum.tagdiv.com/topic/update-tag-div-composer-and-wp-bakery-page-builder-plugin/

It is stated here that there’s a vulnerability in your Theme/Plugin:
https://forum.tagdiv.com/topic/backdoor-in-td-composer-allows-anyone-to-append-css-code-to-the-page-by-making-a/

So what is the final fix to prevent this? Do you expect us to just fix this everytime this happens – knowing that the theme has a vulnerability?

Post count: 21065

Hello!

Follow this guide to clean your WordPress and theme of malware: https://askwpgirl.com/10-steps-remove-malware-wordpress-site/

In the latest update, you won’t have any issues because the new versions of the theme are not compromised.
But if you do not solve the issues before the update, then of course the issue will persist there.

Thank you!

Post count: 91

I solved the problem on my own and spent the whole night in front of the terminal eradicating the threat by cleaning the db and the corrupt files, hoping that everything is working now. Now, unfortunately I’m here to say that this theme has a very serious security problem (for many years) on plugins that are not secure. One of these is the composer plugin and from all the updates you send it is never able to be definitively resolved. Most malfunctions and attacks happen through your plugins! Unfortunately there is also the matter of the speed of the site which is very slow and always due to heavy elements.
I’m really sorry to write it here in this discussion because I’ve been purchasing the template for years but now, before recommending it to some of my clients I’ll think about it more.

Post count: 89

This sums up how I fell to perfection. I have nothing against the devs and the team. I think they’re amazing people, but I am afraid they’ve become a victim of their success with big hacking groups targeting their products, so it’s safer to move.

Post count: 14

Based on the fact that this has been exploited for many years, I have to ask that my purchase be refunded there is no way I will deploy this.

Viewing 24 posts - 1 through 24 (of 24 total)
You must be logged in to reply to this topic.