No search results were found in Documentation!
Hi yassinee, please check the answer from this topic https://forum.tagdiv.com/topic/vulnerability-issue-with-tagdiv-cloud-library-v3-9-2-2/#post-536653
We updated the tagDiv Cloud Library plugin to version 3.9.2, which includes the fix for the XSS vulnerability.
However, all security scanners (Wordfence, WPScan, Patchstack, etc.) are still showing the same vulnerability.
Could you please let us know what we should do in this case, or if there are any additional steps needed to clear these warnings?
We updated the tagDiv Cloud Library plugin to version 3.9.2, which includes the fix for the XSS vulnerability.
However, all security scanners (Wordfence, WPScan, Patchstack, etc.) are still showing the same vulnerability.
Could you please let us know what we should do in this case, or if there are any additional steps needed to clear these warnings?
Hi,
Here are the tools that mention that the fix is in 3.9.2
– https://wpscan.com/vulnerability/0ecaeb97-4f67-4e79-bea8-9c9a6ab7add3/
– https://vdp.patchstack.com/database/wordpress/plugin/td-cloud-library/vulnerability/wordpress-tagdiv-cloud-library-plugin-3-9-cross-site-scripting-xss-vulnerability
– https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/td-cloud-library/tagdiv-cloud-library-39-authenticated-contributor-stored-cross-site-scripting
Another solution is to manually change the plugin version – https://i.imgur.com/2V5Okji.png
Hi, I got this message from Wordfence: The Plugin “tagDiv Cloud Library” has a security vulnerability.
Type: Plugin Vulnerable
Issue Found November 3, 2025 4:26 pm
Critical
Current Plugin Version: 3.9.2 | built on 22.10.2025 10:59
Details: To protect your site from this vulnerability, the safest option is to deactivate and completely remove “tagDiv Cloud Library” until a patched version is available.
Do you know anything about it?
Hi,
If this situation were after the theme update, then make sure that the theme plugins that you had before the theme update are also now installed, like tagDiv Composer, tagDiv Cloud Library, and tagDiv Standard Pack.
Thank you!
Hi,
Here are the tools that mention that the fix is in 3.9.2
– https://wpscan.com/vulnerability/0ecaeb97-4f67-4e79-bea8-9c9a6ab7add3/
– https://vdp.patchstack.com/database/wordpress/plugin/td-cloud-library/vulnerability/wordpress-tagdiv-cloud-library-plugin-3-9-cross-site-scripting-xss-vulnerability
– https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/td-cloud-library/tagdiv-cloud-library-39-authenticated-contributor-stored-cross-site-scripting
Another solution is to manually change the plugin version – https://i.imgur.com/2V5Okji.png
Hi,
I’m on Newspaper 12.7.3 and the tagDiv Cloud Library version is 3.9.2, but the alert is still present for this version.
Thank you,
Hello,
Today, Wordfence issued a critical security alert for the tagDiv Cloud Library plugin. I’m trying to update the theme, but it won’t let me and says it’s already up to date. Can you tell me when you plan to fix this vulnerability?
I’ve included a link to the Wordfence website with the alert and explanation of the issue.
Hi
I deactivated all plugins except for:
• tagDiv Cloud Library
• tagDiv Composer
• tagDiv Standard Pack
…and the problem still persists.
any other suggestions?
Hi,
Here are the tools that mention that the fix is in 3.9.2
– https://wpscan.com/vulnerability/0ecaeb97-4f67-4e79-bea8-9c9a6ab7add3/
– https://vdp.patchstack.com/database/wordpress/plugin/td-cloud-library/vulnerability/wordpress-tagdiv-cloud-library-plugin-3-9-cross-site-scripting-xss-vulnerability
– https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/td-cloud-library/tagdiv-cloud-library-39-authenticated-contributor-stored-cross-site-scripting
Another solution is to manually change the plugin version – https://i.imgur.com/2V5Okji.png
Hi,
This was fixed and is present only in versions smaller than 3.9.2, which is the current plugin version in Newspaper 12.7.3 – https://i.imgur.com/0flN6ED.png
https://vdp.patchstack.com/database/wordpress/plugin/td-cloud-library/vulnerability/wordpress-tagdiv-cloud-library-plugin-3-9-cross-site-scripting-xss-vulnerability
Hi,
When you see shortcodes on your website, it is because one of the plugins is not installed. Please go to Newspaper > plugins and install tagDiv Composer, tagDiv Cloud Library, and in case you had tagDiv Social counter or any other plugin installed, you can install them from there.
Thank you!
Hi,
Wordfence signaled today tagdiv cloud library plugin is vulnerable.
Details here:
Hi Support Team,
I encountered a fatal error on my WordPress site when accessing a category page such as:
https://thekey.news/category/lifestyle/?filter_by=featured
Fatal error: Uncaught Error: Call to a member function is_post_type_archive() on string
in /wp-content/plugins/td-cloud-library/td-cloud-library.php on line 184
I’ve updated the tagDiv Cloud Library plugin to version 3.9.2 (manually), but I’m still receiving a vulnerability warning
Hi,
I’m using Newspaper theme with WPML multilanguage plugin.
I defined 8 single templates with tagdiv Cloud Template and use two languages managed with WPML. If I work with original language I haven’t any problems, but if select my secondary language there is something wrong in the Theme Category Setting.
For the first category, my Post Cloud Library Template list is empty, so I can’t associate my template to the category:

For the next category instead the list is right and complete:

Why?
Thank you.
Enzo
Hello, you have version 3.9.2 and this is the version that has the fix and only previous versions (lower than 3.9.2) have this vulnerability – https://i.imgur.com/xx2opkb.png https://patchstack.com/database/wordpress/plugin/td-cloud-library/vulnerability/wordpress-tagdiv-cloud-library-plugin-3-9-cross-site-scripting-xss-vulnerability?_a_id=241
Other tools like Jetpack and Wordefance will be updated soon.
Thanks!
Hi,
This is the vulnerability reported via Patchstack:
https://patchstack.com/database/wordpress/plugin/td-cloud-library/vulnerability/wordpress-tagdiv-cloud-library-plugin-3-9-cross-site-scripting-xss-vulnerability?_a_id=241
It shows the correct version, but it’s possible that the scan tools haven’t updated their data for some time https://i.imgur.com/LfogY7p.png We hope they will update it soon.
In the meantime, you can manually update the plugin version as shown here:
Thank you!
UPDATE: Sorta…
unable to edit any templates (e.g., post or category templates). When I attempt to open a template for editing, the Composer editor either fails to load, displays a blank screen, or encounters an error, preventing any modifications.
Crucially, the TagDiv Composer seems to work for editing regular pages and posts. I’m guessing the problem is specifically localized to the template editing functionality?
I’ve already done many troubleshooting steps, including:
WordPress & Theme/Composer Versions:
– My WordPress core is up-to-date. 6.8.3
– Dashboard says WP, Themes and Plugins are all up to date. but on the Newspaper updates page it shows I need to update to 12.7.3
– Newspaper theme currently updated to 12.6.9, can’t upto to 12.7.3
Theme Reinstallation Attempts:
– I’ve tried a significant process to ensure theme integrity: I manually downloadeed 12.7.3 from ThemeForest and then performed a fresh, clean update to the current latest version of the Newspaper theme and its associated plugins. This was done to rule out any corrupted files. It wont et me update though, it doesnt complete it.
Site Restore:
– I performed a full site restore from a recent working backup, but the template editing issue persists.
Caching Management:
– I have thoroughly cleared all levels of caching: my WordPress caching plugins (e.g., [mention specific plugin if you use one]), server-side cache via my hosting provider, CDN cache (Cloudflare, etc.), and my browser cache (including incognito mode).
PHP Environment Configuration:
– I have verified my server’s PHP version (currently running 8.3.22)
– I have also manually increased critical PHP limits in my php.ini and wp-config.php, including:
– memory_limit 1024M
– post_max_size 1024M
– upload_max_filesize 1024M
– max_execution_time 600
– max_input_vars 5000
WordPress Core Diagnostics:
– I’ve checked the WordPress Site Health tool, and it reports no issues
– I’ve re-saved permalinks from the WordPress settings.
– I’ve tested editing in different browsers, ccomputers and incognito/private windows.
Plugin Conflicts:
– While pages/posts edit fine, I have also systematically deactivated non-TagDiv plugins that might interact with editors or custom content types to check for conflicts, but the template editing issue remained.
My leading hypothesis is that the problem may be tied to a version mismatch or conflict? My current system is detecting Newspaper Theme 12.6.9, while it seems certain theme components or template assets might have been created or are expecting an environment compatible with Newspaper Theme 12.7.3? This discrepancy appears to specifically affect the way TagDiv Library interacts with or loads template files, as all other Composer functionalities for pages and posts appear to be working correctly.
Could you please provide guidance on this specific issue? I can provide screenshots, access to the browser console, or temporary admin access if needed.
Thank you for your urgent attention to this matter.
-
This reply was modified 9 months by
mikeshecky.
When will there be an update to the Newspaper theme with the secure version of td-cloud-library because our WordPress.com server warns us that the td-cloud-library plugin version 3.9.2 has a major vulnerability?
Hi, since the very last update last week, the search buttons are no longer working. I can do a live search and items do show up but when I hit the button, the search results page wont open and a fatal error page will pop up instead. I have enabled debug and this is what I get:
Fatal error: Uncaught TypeError: Cannot access offset of type array on string in /var/www/html/news/wp-content/plugins/td-composer/legacy/common/wp_booster/td_util.php:1196 Stack trace: #0 /var/www/html/news/wp-content/plugins/td-composer/legacy/common/wp_booster/td_util.php(340): td_util::get_template_id() #1 /var/www/html/news/wp-content/plugins/td-composer/legacy/common/wp_booster/td_wp_booster_functions.php(513): td_util::check_header() #2 /var/www/html/news/wp-includes/class-wp-hook.php(324): td_load_css_fonts() #3 /var/www/html/news/wp-includes/class-wp-hook.php(348): WP_Hook->apply_filters() #4 /var/www/html/news/wp-includes/plugin.php(517): WP_Hook->do_action() #5 /var/www/html/news/wp-includes/script-loader.php(2299): do_action() #6 /var/www/html/news/wp-includes/class-wp-hook.php(324): wp_enqueue_scripts() #7 /var/www/html/news/wp-includes/class-wp-hook.php(348): WP_Hook->apply_filters() #8 /var/www/html/news/wp-includes/plugin.php(517): WP_Hook->do_action() #9 /var/www/html/news/wp-includes/general-template.php(3192): do_action() #10 /var/www/html/news/wp-content/plugins/td-composer/legacy/Newspaper/header.php(8): wp_head() #11 /var/www/html/news/wp-content/plugins/td-composer/td-composer.php(254): require_once(‘…’) #12 /var/www/html/news/wp-includes/class-wp-hook.php(324): {closure:/var/www/html/news/wp-content/plugins/td-composer/td-composer.php:249}() #13 /var/www/html/news/wp-includes/class-wp-hook.php(348): WP_Hook->apply_filters() #14 /var/www/html/news/wp-includes/plugin.php(517): WP_Hook->do_action() #15 /var/www/html/news/wp-content/themes/Newspaper/header.php(2): do_action() #16 /var/www/html/news/wp-includes/template.php(810): require_once(‘…’) #17 /var/www/html/news/wp-includes/template.php(745): load_template() #18 /var/www/html/news/wp-includes/general-template.php(48): locate_template() #19 /var/www/html/news/wp-content/plugins/td-cloud-library/wp_templates/tdb_view_search.php(8): get_header() #20 /var/www/html/news/wp-includes/template-loader.php(106): include(‘…’) #21 /var/www/html/news/wp-blog-header.php(19): require_once(‘…’) #22 /var/www/html/news/index.php(17): require(‘…’) #23 {main} thrown in /var/www/html/news/wp-content/plugins/td-composer/legacy/common/wp_booster/td_util.php on line 1196
I have tried to use another cloud template for the search page, I have tried editing the existing one and saving… but nothing helps same error all the time.
Any clues on what is going on?
Thanks in advance,
Jose
Hi,
I’ve updated the Newspaper theme to the latest version (12.7.3), but the issue still persists. The tagDiv Cloud Library (v3.9.2) plugin is showing as vulnerable, and even after updating the theme, the problem remains unresolved.
Could you please advise on the next steps to fully fix this issue?
Thank you for your assistance.
Best regards,
Hi,
Please make sure that the thene plugins you used before the update are installed. Those can be installed from Newspaper > plugins. You should have installed and activated tagDiv Composer, cloud library and possible tagdiv standard pack.
Thank you!
Hi,
This is because some theme plugins are no longer installed. Go to Newspaper > plugins and make sure that tagDiv Composer, cloud Library, and tagDiv Standard Pack are installed.
Thank you!