Home User profile
pbn
tagDiv Member
This user did not write anything. So we are just showing here some random text to make the profile page look nice :)
pbn
tagDiv Member

For those of us on customized platforms, it’s not just simple to upgrade to the newest version. With our security policy, we usually only get hit when hacks use specifically whitelisted admin files such as admin-ajax.php which this hack does.

I’m not 100% certain as my change has been only live for a hour, but if you disable the td_ajax_update_panel action that the exploit uses, you can prevent the exploit from occurring. This is a stop-gap measure as this will also prevent you from updating any theme settings from the panel, so make sure you have them where you like them if you do this.

pbn
tagDiv Member

For those of us on very customized older versions and can’t really upgrade without a lot of work, does anyone know what files/code to modify in order to patch this vulnerability. We don’t even use the ads function so I removed the code that displays them from the template, however that does not stop the code from getting injected in the header ads field in the DB. TIA.

pbn
tagDiv Member

Thanks Chris. I figured the Shim wasn’t intended for Newspaper but I’m getting the same problems. I just picked this up so won’t have access to older VC versions. Looks like I’ll have to stick to uninstalling / reinstalling the VC plugin every few days till this is resolved.

pbn
tagDiv Member

Is this SHIM being worked on for the Newspaper theme? I have the Newspaper theme and the visual composer problem is affecting us as well? We have Newspaper 4.6.3 running on a WAMP stack. We get 2500 visits a day tops so that may be why it takes longer to affect us than larger sites?

I don’t get CPU usage warnings all I see is that the time to first byte on our site seems to slip everyday. I moved our site to an entirely different server and it helped for a day. The first day the TTFB was 900ms, today it’s 2000ms by the end of the week it’ll be back at 8000ms just like when we hosted it on a different server.

If I disable the Visual Composer, the time to first byte goes from 2000ms to 600ms.

The shim helps keep some of my article elements inline but all the columns don’t work. Disabling the Visual Composer also messes up the sliders on the front page and the shim doesn’t fix that.

Is there going to be a fix for this soon or do I need to manually rebuild my homepage?

I also noticed that if I removed and then reinstalled the Visual Composer Plugin, that it “reset” the issue and I’m back to 900ms TTFB. I presume it will just slip away again though…

  • This reply was modified 11 years by pbn.
Viewing 4 posts - 1 through 4 (of 4 total)