Ad injection and critical vulnerability in Cloud Library plugin

Posted in: Newspaper
Post count: 11

Wordfence has indicated a vulnerability in the Cloud Library plugin. I also now see an ad being injected into the site. How do we correct this? When will a safe version of the Cloud Library plugin be available? I can’t run the site without this plugin, but it has already caused problems. Please advise a fix ASAP.
I have no ads set up, and none should be displaying.

The following is the message from Wordfence. Please note that this vulnerability has been listed for several weeks.

Results Found
1
The Plugin “tagDiv Cloud Library” has a security vulnerability.
Type: Plugin Vulnerable
Issue Found December 19, 2025 11:09 am
Critical
Ignore
Details
Plugin Name: tagDiv Cloud Library
Current Plugin Version: 3.9.2 | built on 22.10.2025 10:59
Details: To protect your site from this vulnerability, the safest option is to deactivate and completely remove “tagDiv Cloud Library” until a patched version is available. Get more information.(opens in new tab)
Vulnerability Information: https://www.wordfence.com/threat-intel/vulnerabilities/id/f97414f7-3544-4ecf-908a-a0215e322e68?source=plugin(opens in new tab)
Vulnerability Severity: 6.4/10.0 (Medium)

Post count: 35449

Hi,

If you are using plugin version 3.9.2, there should be no issues.
You can refer to the following screenshots for confirmation: https://i.imgur.com/avYb97q.png

View post on imgur.com


According to the developers at Wordfence, the warning message may still appear even when version 3.9.2 is installed. This happens because the plugin information includes the build timestamp:(Version: 3.9.2 | built on 22.10.2025 10:59)
This is not a problem, and the plugin is no longer vulnerable. The version number itself will be updated in the next theme update, which is expected to be released in January.

Thank you!

Post count: 11

This malicious ad injection is still an issue. I may need to pay a developer to clean the site. This has been a consistent issue since using the Newspaper theme and is very disappointing.

Post count: 9544

7+ years using the theme; never been hacked.

Post count: 11

Good for you. That’s not my experience

Post count: 7

Is there any solution for this ?

Post count: 35449

Hi aminier86, please ensure that you have the latest version of the theme Newsapper 12.7.5, where the cloud library version is 3.9.4, and that vulnerability has been fixed.

Viewing 7 posts - 1 through 7 (of 7 total)
You must be logged in to reply to this topic.