TD Composer Flagged as Security Risk

Posted in: Newspaper
Post count: 3

TD Composer is currently being flagged with my web host as containing security vulnerabilities. Particularly with version 5.4.5 is that the most current version as I am not seeing any version numbers at this time.

Post count: 20688

Hi,

The latest theme version includes composer 5.4.5, which contains fixes for all the vulnerabilities know at this time related to it.

However, in such cases we have to contact the biggest vulnerability database providers, like Patchstack and Wordfence. We contacted both, yet so far we only heard back from Wordfence which should hopefully be updating their database soon. Nothing from Patchstack yet.

The hosting providers are most likely sourcing their information from them, as they don’t actually check or scan the plugin code. Until Patchstack and Wordfence acknowledge the fixes and mark them as fixed, there’s nothing else that we can do, the composer will continue to get flagged by automated tools, while containing the actual fixes. These things always seem to take a lot of time unfortunately. We are very sorry for the situation.

Thank you!

Post count: 50

Could you please confirm whether CVE-2026-39712 is fixed in tagDiv Composer 5.4.5, and ask WPScan, Patchstack and Wordfence to update the patched version metadata? Jetpack Scan is still flagging td-composer 5.4.5 because the vulnerability databases list affected versions as <= 5.4.3 but also show “no known fix”.

Post count: 20688

@RECORD EUROPA

We heard back From Patchstack yesterday, they acknowledged the fixes included with composer 5.4.5:

CVE-2026-39712 -> https://patchstack.com/database/wordpress/plugin/td-composer/vulnerability/wordpress-tagdiv-composer-plugin-5-4-3-arbitrary-shortcode-execution-vulnerability

CVE-2026-39692 -> https://patchstack.com/database/wordpress/plugin/td-composer/vulnerability/wordpress-tagdiv-composer-plugin-5-4-3-cross-site-scripting-xss-vulnerability

We did not hear back from Wordfence yet. We collaborate with them frequently, but sometimes it takes them a while.

We did not hear back from WP Scan also. I believe Jetpack security is powered by WP Scan, they don’t pull their data from Patchstack or Wordfence.

Until every one of them knows about the fix, those vulnerabilities will remain marked as active or without a known fix. I hope we hear from them soon. Sorry for this situation.

Thank you!

Viewing 4 posts - 1 through 4 (of 4 total)
The forum ‘Newspaper’ is closed to new topics and replies.