Wordfence has indicated a vulnerability in the Cloud Library plugin. I also now see an ad being injected into the site. How do we correct this? When will a safe version of the Cloud Library plugin be available? I can’t run the site without this plugin, but it has already caused problems. Please advise a fix ASAP.
I have no ads set up, and none should be displaying.
The following is the message from Wordfence. Please note that this vulnerability has been listed for several weeks.
Results Found
1
The Plugin “tagDiv Cloud Library” has a security vulnerability.
Type: Plugin Vulnerable
Issue Found December 19, 2025 11:09 am
Critical
Ignore
Details
Plugin Name: tagDiv Cloud Library
Current Plugin Version: 3.9.2 | built on 22.10.2025 10:59
Details: To protect your site from this vulnerability, the safest option is to deactivate and completely remove “tagDiv Cloud Library” until a patched version is available. Get more information.(opens in new tab)
Vulnerability Information: https://www.wordfence.com/threat-intel/vulnerabilities/id/f97414f7-3544-4ecf-908a-a0215e322e68?source=plugin(opens in new tab)
Vulnerability Severity: 6.4/10.0 (Medium)
Hi,
If you are using plugin version 3.9.2, there should be no issues.
You can refer to the following screenshots for confirmation: https://i.imgur.com/avYb97q.png
According to the developers at Wordfence, the warning message may still appear even when version 3.9.2 is installed. This happens because the plugin information includes the build timestamp:(Version: 3.9.2 | built on 22.10.2025 10:59)
This is not a problem, and the plugin is no longer vulnerable. The version number itself will be updated in the next theme update, which is expected to be released in January.
Thank you!
