The Plugin “tagDiv Composer” has a security vulnerability.

Posted in: Newspaper
Post count: 4

The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Post count: 35449

Hi,
That security vulnerability was fixed, just make sure that you are using the latest theme version, Newsapper v12.7.4, with tagDiv Composer version 5.4.3 – https://patchstack.com/database/Wordpress/Plugin/td-composer/vulnerability/wordpress-tagdiv-composer-plugin-5-4-2-cross-site-scripting-xss-vulnerability?_s_id=cve
https://forum.tagdiv.com/how-to-update-the-theme-2/
Thank you!

Viewing 3 posts - 1 through 3 (of 3 total)
The forum ‘Newspaper’ is closed to new topics and replies.