Hi Newspaper theme, we are getting pinged by Jetpack that your theme has a strong security flaw. This has been reported for at least a month now. Is anyone working on this?
Vulnerable Plugin: td-cloud-library (version 3.9.2 | built on 22.10.2025 10:59)
Vulnerability found in plugin
Hi,
This was fixed and is present only in versions smaller than 3.9.2, which is the current plugin version in Newspaper 12.7.3 – https://i.imgur.com/0flN6ED.png
Here are the tools that mention that the fix is in 3.9.2
– https://wpscan.com/vulnerability/0ecaeb97-4f67-4e79-bea8-9c9a6ab7add3/
– https://vdp.patchstack.com/database/wordpress/plugin/td-cloud-library/vulnerability/wordpress-tagdiv-cloud-library-plugin-3-9-cross-site-scripting-xss-vulnerability
– https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/td-cloud-library/tagdiv-cloud-library-39-authenticated-contributor-stored-cross-site-scripting
Another solution is to manually change the plugin version – https://i.imgur.com/2V5Okji.png
Thank you!
Hi Calin. I have the same problem. For the manual solution, what should I put in place of 3.9.2 in the plugin code?