4 months later, is this fixed? Have you finally implemented Nonce Validation and Unauthenticated Request Filtering for all td_ajax_ account functions????
-
This reply was modified 6 days by
E K.
Yes, same here!!! Any updates?
They are all protected, can give you full access to the backend for you to see. Also, what do you mean by “purchase the CDN”. Finally why do you avoid the question: when are you going to implement Nonce Validation and Unauthenticated Request Filtering for all td_ajax_ account functions. It’s been years and several attacks that we’ve gone through – hacked twice already. Why don’t you fix it?
Also, we don’t use tagDiv Opt-in Builder plugin and Enable user registration” option is disabled.

the website is https://thevou.com
Appreciate the advice, we have both, Wordfence and Cloudflare premium running but I was not asking about 3rd party tools but when are you going to implement Nonce Validation and Unauthenticated Request Filtering for all td_ajax_ account functions. It’s been years and several attacks that we’ve gone through – hacked twice already. Please fix it.

ONGOING!



This is insane. The user has reported a security vulnerability or code injection in td_ajax.php more than 4 months ago and your only answer is that “I made a new notice to our developers; unfortunately, this is all I can do.” REALLY? Calin, REALLY?
Thank you, that fixed it but caused a new issue we never had before:
WordPress database error Commands out of sync; you can’t run this command now for query SELECT option_value FROM wp_options WHERE option_name = ‘wc_pending_batch_processes’ LIMIT 1 made by shutdown_action_hook, do_action(‘shutdown’), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\WooCommerce\Internal\BatchProcessing\BatchProcessingController->Automattic\WooCommerce\Internal\BatchProcessing\{closure}, Automattic\WooCommerce\Internal\BatchProcessing\BatchProcessingController->remove_or_retry_failed_processors, Automattic\WooCommerce\Internal\BatchProcessing\BatchProcessingController->get_enqueued_processors, get_option
Do you want me to give you access to our server??
WordPress did not recognise the zip as a plugin. I tried installing on 3 wordpress websites, same error – the zip is not a wordpress plugin.
Notice? It is an error that takes down the server by creating 200MB of log files in 24h! NOTICE….
And, I am asking again, what do I do with the shared ZIP file??
Thanks, how do I install this?
My reply to Betina
I know what the errors suggest, as we had WordPress developers looking at our installation. They asked us NOT TO HIDE the error, because that’s not a fix and the error will still shut down the server. And, TO GET IN TOUCH with the theme developers (THAT IS YOU) as these issues are theme related. Moreover, they insisted that both Woocommerce and WordPress are free of these bugs and that, again, they are theme-related.
Please advise,
I am gonna make this coversation transparent here for others with similar problem to learn and hopefully receive a better customer support from you than me.
Betina’s reply to me:
I’ve checked and the issue seems to be from Woocommerce. As a temporary fix, you may disable the WP_DEBUG.
The error you’re seeing, “Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the woocommerce-gateway-stripe domain was triggered too early.”, typically occurs when the WooCommerce Stripe payment gateway plugin is attempting to load its translations before WordPress is fully ready to handle them. This issue usually happens because the plugin is calling the translation loading function (_load_textdomain_just_in_time) at a point when WordPress hasn’t fully initialized or when the init hook has not yet fired.
Developers often release patches to address such issues.
The error message you’re encountering, “Function WP_Block_Patterns_Registry::register was called incorrectly. Pattern content must be a string. (This message was added in version 5.5.0.)”, typically occurs when there is an issue with the way a block pattern is being registered in WordPress. Specifically, this error suggests that the content passed to the register() function of WP_Block_Patterns_Registry is not a valid string, which is required.
Thanks,
Bettina
Email sent with detailed explanation, link to this chat, and the required credentials. Looking fwd to a swift resolution before the server company kicks us out!
Installed, but what is the changelog of version: 12.7? Unable to find it anywhere.
Yep, same here.
It kind of worked. Kind of because the pic is still clickable – and opens on a new page, and the magnifier icon is still present.
How can I stop both?
Please advise,
I think we should be able to disable the Whatsapp sharing button from the theme, how do we do that?
https://ibb.co/d46bd4T
Huh? What do you mean you don’t control this? It is your theme.
Just did, thank you. I have also replied that the issue persists.
I have just disabled all plugins, but the issue persists. Please advise
You keep ignoring my question. Is this theme suffering from development fault that impacts the SEO badly, and you guys have no idea how to fix?
That’s how it looks right now since you are pretending that the question does not exist.
My question is still standing after 24 hours with no reply from you, so maybe your silence is the answer..

