Cross-Site Request Forgery to Stored Cross-Site Scripting

Posted in: Newspaper
Post count: 4

I was just alerted to this:

The tagDiv Composer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3. This is due to missing or incorrect nonce validation within the td_ajax_get_views AJAX action. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Source: Wordfence

Post count: 21065

Hello!

I will add this issue to our investigation list.

Thank you!

Post count: 31

Hello,

Is it resolved? I also have the same alert on my sites. Should I update the theme? I received email alerts from the Wordfence plugin

Thank you!

Post count: 21065

Hello!

Currently, we are investigating this issue.

Thank you!

Viewing 4 posts - 1 through 4 (of 4 total)
The forum ‘Newspaper’ is closed to new topics and replies.