tagDiv Cloud Library Plugin < 2.7 is vulnerable security

Posted in: Newspaper
Post count: 100

Hello,

WordPress tagDiv Cloud Library Plugin < 2.7 is vulnerable to Privilege Escalation

https://patchstack.com/database/vulnerability/td-cloud-library/wordpress-tagdiv-cloud-library-plugin-2-7-unauthenticated-arbitrary-user-metadata-update-to-privilege-escalation-vulnerability?_a_id=110

Our server has been reporting a security breach related to tagDiv Cloud for several days, what should be done?

Post count: 102

It’s in your link: Update to the current version, which is 2.7.

Post count: 35449

Hi dlicoppe,
Normally there should be no problems with the latest version which is 2.7 -> https://i.imgur.com/L4WD1sk.png only with lower versions, but I understand that message can create suspicions.
Thank you!

Post count: 8

I think what happened here is the vulnerability monitors have seen the message saying vulnerable in versions < 2.7 and concluded that 2.7 was vulnerable.

Without knowing the details of the exploit, I notice the person who found the issue reports that Newspaper 12.4 is not vulnerable, which came with TagDiv Cloud Library 2.7, so I believe that 2.7 is definitely OK, and it’s just a false alert.

WPScan reports it is as vulnerable on < 2.7 and fixed on 2.7: https://wpscan.com/vulnerability/4eafe111-8874-4560-83ff-394abe7a803b

Viewing 4 posts - 1 through 4 (of 4 total)
The forum ‘Newspaper’ is closed to new topics and replies.