{"id":1190350,"date":"2023-10-09T16:48:01","date_gmt":"2023-10-09T20:48:01","guid":{"rendered":"https:\/\/www.prime-wow.com\/?p=1190350"},"modified":"2023-10-09T16:48:01","modified_gmt":"2023-10-09T20:48:01","slug":"thousands-of-wordpress-sites-have-been-hacked-through-tagdiv-plugin-vulnerability","status":"publish","type":"post","link":"https:\/\/www.prime-wow.com\/?p=1190350","title":{"rendered":"Thousands of WordPress sites have been hacked through tagDiv plugin vulnerability"},"content":{"rendered":"<div id=\"rss-wrap\">\n<figure class=\"intro-image intro-left\">\n  <img decoding=\"async\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2023\/10\/scam-website-800x534-1.jpe\" alt=\"Thousands of WordPress sites have been hacked through tagDiv plugin vulnerability\" \/><\/p>\n<p class=\"caption\" style=\"font-size:0.8em\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/07\/scam-website.jpeg\" class=\"enlarge-link\" data-height=\"667\" data-width=\"1000\">Enlarge<\/a> (credit: <a rel=\"nofollow\" class=\"caption-link\" href=\"https:\/\/www.gettyimages.com\/\">Getty Images<\/a>)<\/p>\n<\/figure>\n<div><a name=\"page-1\" \/><\/div>\n<p>Thousands of sites running the WordPress content management system have been hacked by a prolific threat actor that exploited a recently patched vulnerability in a widely used plugin.<\/p>\n<p>The vulnerable plugin, known as tagDiv Composer, is a mandatory requirement for using two WordPress themes: <a href=\"https:\/\/themeforest.net\/item\/newspaper\/5489609\">Newspaper<\/a> and <a href=\"https:\/\/themeforest.net\/item\/newsmag-news-magazine-newspaper\/9512331\">Newsmag<\/a>. The themes are available through the Theme Forest and Envato marketplaces and have more than 155,000 downloads.<\/p>\n<p>Tracked as CVE-2023-3169, the vulnerability is what\u2019s known as a cross-site scripting (XSS) flaw that allows hackers to inject malicious code into webpages. Discovered by Vietnamese researcher <a href=\"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/researchers\/truoc-phan\">Truoc Phan<\/a>, the vulnerability carries a severity rating of 7.1 out of a possible 10. It was partially fixed in tagDiv Composer version 4.1 and fully patched in 4.2.<\/p>\n<\/div>\n<p><a href=\"https:\/\/arstechnica.com\/?p=1974522#p3\">Read 8 remaining paragraphs<\/a> | <a href=\"https:\/\/arstechnica.com\/?p=1974522&amp;comments=1\">Comments<\/a><\/p>\n<p>&#013;<br \/>\n&#013;<br \/>\nSource: Ars Technica &#8211; <a href=\"https:\/\/arstechnica.com\/?p=1974522\" target=\"_blank\" rel=\"noopener\">Thousands of WordPress sites have been hacked through tagDiv plugin vulnerability<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Enlarge (credit: Getty Images) Thousands of sites running the WordPress content management system have been hacked by a prolific threat actor that exploited a recently patched vulnerability in a widely used plugin. The vulnerable plugin, known as tagDiv Composer, is &hellip; <a href=\"https:\/\/www.prime-wow.com\/?p=1190350\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":1190351,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27,110],"tags":[73],"class_list":["post-1190350","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ars-technica","category-unfiltered-rss","tag-ars-technica"],"_links":{"self":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1190350","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1190350"}],"version-history":[{"count":0,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1190350\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/media\/1190351"}],"wp:attachment":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1190350"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1190350"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1190350"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}