"wp-zexit" malware and newspaper theme problem – please see

Posted in: Newspaper
Post count: 62

i have the same problem

please see this link

wp-zexit
byu/cdbessig inWordPress

Post count: 62

when i check my site in google results my website were redirect to this url

specialnewpaper.com

i think this is malware

please check your plugin folder in your host

for this plugin ! wp-zexit

  • This reply was modified 2 years by javid.
Post count: 12

We have been affected by the same vulnerability and hopefully we managed to fix it (for now). Please release a security update asap.

Post count: 21065
Post count: 20688

We are investigating this issue at this time. It would help us if we could analyze the respective plugin “wp-zexit”. If anyone can provide it, or is currently having issues caused by it and needs help, please send us an email at contact@tagdiv.com and let us know.

Thank you!

Post count: 10

My website also encountered a similar issue when I was checking for malware using the Wordfence plugin. I ended up removing the plugin and investigating why it appeared. It turns out it was related to Tagdiv.

Post count: 5

Did you guys release new update which solved this and removed all the bad code or is it just me?

Post count: 21065

Hello!

Unfortunately, we can’t delete your database if you have any compromised files.
In the next update, you won’t have any issues because the new versions of the theme are not compromised.
But if you do not solve the issues before the update, then of course the issue will persist there.

Thank you!

Post count: 5

Where in the database can these bad things be found?

Post count: 21065

Hello @inserte !

Usually, there is more than one place. That’s why you should delete every hacked path.
Follow this guide to clean your WordPress and theme of malware: https://askwpgirl.com/10-steps-remove-malware-wordpress-site/

Thank you!

Post count: 1

Hi @inserte,

Search your database for td_live_css_local_storage we found the trojan code placed inside here in wp-options. TagDiv should this table be in the wp-options database or can we delete it? We have now updated wordpress and newspaper along with the plugins with the theme so we are hoping the backdoor has been fixed.

Post count: 21065

Hello @cpritch!

Please delete the values from td_live_css_local_storage.

Thank you!

Post count: 8

Hellow team Tag Div support,
brand’s antivirus Eset and Karspesky have blocked my site by malware problem with plugin wpzexit and admin user greeceman. I have update Newspaper theme and plugins a the last version 12.6. And the pop up alert antivirus finish, but my website continue blocked by background white when user with antivirus enter my website. I have less visitor and my Newspaper loose credibility.

Tad Div Suport Company may speak with antivirus’s business for help to we buyers from Newspaper theme? and that antivirus companies delete his restrictions.

Gracias.
Pedro García Ródenas
Web Site:
https://elperiodicodeyecla.com/

Post count: 1

this query clears the td_live_css_local_storage value and doesn’t depend on the database prefix, run it as-is, just run it on your wp database

https://pastebin.com/3rxY9buN

Post count: 91

hi,
i have the problem with wp-zexit. My version is newspaper: 11.5.1

This the code of the malware inside in some page: https://prnt.sc/dr7LcY9fg5SR

How do I solve the problem? If you want I can provide you with the credentials. The issue is quite urgent

Post count: 21065

Hello @ersandrino !

I’ve already replied to this topic: https://forum.tagdiv.com/topic/update-tag-div-composer-and-wp-bakery-page-builder-plugin/#post-488145

Please do not write on multiple topics!

Thank you so much for your understanding!

Post count: 3

Hi @bettina,
We have several sites with the Newspaper theme, I’ve tried to update one of them from 10.3.9.1 to the latest Newspaper but the site got broken so I had to downgrade it again.

Is there a way to update only the tagDiv plugin and keeping the Newspaper theme on the current version?

I’ll wait to your confirmation.

Thanks,

Marcos

Post count: 80

What a mess.

Post count: 21065

Hello @irugoy!

After you update the theme, make sure you have all the tagdiv plugins installed and activated (the Standard Pack plugin as well if you use default templates).
Your site shouldn’t be broken.

Thank you!

Post count: 3

Hi @bettina,

When I tried to update the Theme, the Theme got updated correctly but all the TD-Plugins got deactivated.

When I tried to Update the plugins and reactivate them (from Newspaper/Plugins section or manually from WordPress/Plugins) I got several Ajax Errors and could not reactivate them, so the site did not work properly at all.

Any idea why I did get that Ajax Errors on the Newspaper/Plugins/Update modal window?

Thanks,

Post count: 21065

Hello @irugoy!

Deactivate all the non-tested plugins with our theme before updating. It could be from a plugin conflict or some settings from any plugin or security plugin.

Thank you!

Post count: 3

Ok @betting,

I’ll have to create a staging environment to do those tests since last time I did the upgrade on live and it was critical since the theme got upgraded but not the plugins.

I’ll let you know once it’s done.

Best,

Post count: 29

Hello tagdiv support. I am asking for something specific here please read

I’m having such a hard time removing this malware. My hosting company removed it one time, apparently via editing the database, but it has come back. They have removed it again, but they said it is only a matter of time till the issue re-surfaces.

I am running into many issues; I will mentioned three of them:
(1) Updating my version of Newspaper breaks my site; (2) updating td-composer with a newer version is apparently not possible without updating Newspaper, and (3) I tried running the SQL query mentioned by mmorselli somewhere on these pages and got nothing but errors

I am sure I am speaking for a lot of Newspaper users when I request the following:
(A) A patch, please. If these problems are due to a vulnerability in your plugin, why not release a patch? Perhaps a temporary plugin that just cleans it up?
(B) In the short term, if a patch is not forthcoming, can you please provide a version of td-composer that removes the vulnerability and can be installed on older versions of Newspaper?
(C) If no patch, can you please provide a removal guide FOR DUMMIES with simple to understand steps. Perusing many posts on these forums where people say different things has not worked out for me.

Thanks

Post count: 21065

Hello @kurdi!

We will take into consideration your queries.
Please respect all the steps before updating the theme, and make sure that you are up-to-date and not infected. If your files are infected and you do the update, then the infected files will remain there, no matter which version of the theme or plugin you use. The main step is to delete every infected file from your installation, and then everything will be OK and not compromised.
Let us know about your issues and which errors you encountered there, so we can help you all. You can also send us an email, so we can check all these issues.

Thank you!

Post count: 268

Okay Bettina, but can’t you just tell us where to find the back door that injects the malicious code on the database so that we can remove it perhaps by making simple changes to the affected php file?

Viewing 25 posts - 1 through 25 (of 34 total)
The forum ‘Newspaper’ is closed to new topics and replies.