TagDiv Composer Vulnerability warning

Posted in: Newspaper
Post count: 11

WordFence is warning of a “critical vulnerability” with the TagDiv composer plugin. Is there a patch or update expected soon?

Post count: 6

I got this warning too.

Post count: 23

same here

Post count: 16

WordPress tagDiv Cloud Library plugin <= 3.9.4 – Cross Site Scripting (XSS) vulnerability???

Post count: 2

tagDiv Composer <= 5.4.5 – Reflected Cross-Site Scripting

The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/td-composer/tagdiv-composer-545-reflected-cross-site-scripting

Post count: 20685

Hi,

We are aware of these issues and they are currently being fixed. A theme update will be released soon, most likely this week.

Thank you!

Viewing 6 posts - 1 through 6 (of 6 total)
You must be logged in to reply to this topic.