on May 2nd we received an alert from Wordfence Security Plugin (WordPress) that Tag Div Composer has a vulnerability threat contained. here is the URL for threat: https://www.wordfence.com/threat-intel/vulnerabilities/id/2bd6b66d-f33e-4287-850b-a199de72f6ad?source=plugin
Bettina
Now we have a second critical warning, same as from Wordfence but this time from Jeptack (owned by WordPress). I think you should escalate your investigation.
Kevin
We did not indicate that the 2nd vulnerability warning was Admin. Bar plugin, we received this message (same as Wordfence warning) from Jetpack (owned by WordPress). Have you done anything to address this issue, affecting all users?
Thanks,
Marcusdoc,
Thanks for the reply. I have been holding off on the 12.7.1 update as bugs often take time to work out with Tagdiv. I just installed 12.7.1, which updated composer. It appears Tagdiv fixed their vulnerability issue now.
Kevin
