tagdiv cloud library has a security vulnerability

Posted in: Newspaper
Post count: 5

Hi,

Wordfence signaled today tagdiv cloud library plugin is vulnerable.

Details here:

https://www.wordfence.com/threat-intel/vulnerabilities/id/f97414f7-3544-4ecf-908a-a0215e322e68?source=plugin

Post count: 35449

Hi,
This was fixed and is present only in versions smaller than 3.9.2, which is the current plugin version in Newspaper 12.7.3 – https://i.imgur.com/0flN6ED.png
https://vdp.patchstack.com/database/wordpress/plugin/td-cloud-library/vulnerability/wordpress-tagdiv-cloud-library-plugin-3-9-cross-site-scripting-xss-vulnerability

Post count: 5

Hi,
I’m on Newspaper 12.7.3 and the tagDiv Cloud Library version is 3.9.2, but the alert is still present for this version.
Thank you,

Post count: 35449

Hi,
Another solution is to manually change the plugin version – https://i.imgur.com/2V5Okji.png
Thank you!

Post count: 5

Hi,

Maybe it would be better to discuss with wordfence team to remove the alert from the daily database updates of their tool if plugin version 3.9.2 is already fixed?

Or maybe tagdiv could release an update with 3.9.3?

Changing manually the version is not a real/fair solution (my humble opinion).

Thank you,

Post count: 35449

Hi,
We already did this. The Wordfence free version receives updates to the plugin software itself, but security updates for firewall rules and malware signatures are delayed by 30 days compared to the Premium version. https://wordpress.org/plugins/wordfence/https://i.imgur.com/V5Pqwry.png

Post count: 9

We updated the tagDiv Cloud Library plugin to version 3.9.2, which includes the fix for the XSS vulnerability.
However, all security scanners (Wordfence, WPScan, Patchstack, etc.) are still showing the same vulnerability.

Could you please let us know what we should do in this case, or if there are any additional steps needed to clear these warnings?

Post count: 35449
Viewing 8 posts - 1 through 8 (of 8 total)
The forum ‘Newspaper’ is closed to new topics and replies.