Hi,
Wordfence signaled today tagdiv cloud library plugin is vulnerable.
Details here:
Hi,
This was fixed and is present only in versions smaller than 3.9.2, which is the current plugin version in Newspaper 12.7.3 – https://i.imgur.com/0flN6ED.png
https://vdp.patchstack.com/database/wordpress/plugin/td-cloud-library/vulnerability/wordpress-tagdiv-cloud-library-plugin-3-9-cross-site-scripting-xss-vulnerability
Hi,
I’m on Newspaper 12.7.3 and the tagDiv Cloud Library version is 3.9.2, but the alert is still present for this version.
Thank you,
Hi,
Another solution is to manually change the plugin version – https://i.imgur.com/2V5Okji.png
Thank you!
Hi,
Maybe it would be better to discuss with wordfence team to remove the alert from the daily database updates of their tool if plugin version 3.9.2 is already fixed?
Or maybe tagdiv could release an update with 3.9.3?
Changing manually the version is not a real/fair solution (my humble opinion).
Thank you,
Hi,
We already did this. The Wordfence free version receives updates to the plugin software itself, but security updates for firewall rules and malware signatures are delayed by 30 days compared to the Premium version. https://wordpress.org/plugins/wordfence/ – https://i.imgur.com/V5Pqwry.png
We updated the tagDiv Cloud Library plugin to version 3.9.2, which includes the fix for the XSS vulnerability.
However, all security scanners (Wordfence, WPScan, Patchstack, etc.) are still showing the same vulnerability.
Could you please let us know what we should do in this case, or if there are any additional steps needed to clear these warnings?
Hi yassinee, please check the answer from this topic https://forum.tagdiv.com/topic/vulnerability-issue-with-tagdiv-cloud-library-v3-9-2-2/#post-536653