Hi Support,
I’m using the tagDiv Cloud Library plugin on my WordPress site and noticed there is a Cross-Site Scripting (XSS) vulnerability in versions before 3.9.2.
Could you confirm if updating to version 3.9.2 fully fixes this issue? Any advice to secure my site would be appreciated.
Thank you,
Hi,
Updating the theme to the latest version, Newspaper 12.7.3, should resolve that problem.
The Ultimate WordPress Security Guide – Step by Step (2025) – https://www.wpbeginner.com/wordpress-security/
Thank you!
Hi,
I’ve updated the Newspaper theme to the latest version (12.7.3), but the issue still persists. The tagDiv Cloud Library (v3.9.2) plugin is showing as vulnerable, and even after updating the theme, the problem remains unresolved.
Could you please advise on the next steps to fully fix this issue?
Thank you for your assistance.
Best regards,
Hello, Jetpack has identified the same vulnerability and indicates that it is high risk.
I have the theme updated and I have already uninstalled and reinstalled the plugin (via the theme, which supposedly retrieves the latest version from your servers), but the problem persists!
However, the information available at: https://wpscan.com/vulnerability/0ecaeb97-4f67-4e79-bea8-9c9a6ab7add3/
Says it’s resolved, but how can we access the latest (fixed) version of the plugin?
They can help us.
Thank you.
Hi,
This is the vulnerability reported via Patchstack:
https://patchstack.com/database/wordpress/plugin/td-cloud-library/vulnerability/wordpress-tagdiv-cloud-library-plugin-3-9-cross-site-scripting-xss-vulnerability?_a_id=241
It shows the correct version, but it’s possible that the scan tools haven’t updated their data for some time https://i.imgur.com/LfogY7p.png We hope they will update it soon.
In the meantime, you can manually update the plugin version as shown here:
Thank you!
please check this even we have last version
Hi,
The provided screenshots mention that only versions smaller than 3.9.2 are affected – https://i.imgur.com/ONjsD5b.png – https://wpscan.com/vulnerability/0ecaeb97-4f67-4e79-bea8-9c9a6ab7add3/
We’ve already updated to version 3.9.2, which should include the security fix.
However, some security scan tools are still reporting the same vulnerability — possibly because their databases haven’t been updated yet.
Could you please provide a solution or official confirmation to help us clear this false warning?
If there are any additional steps or patches required beyond version 3.9.2, please let us know.
Hi,
Here are the tools that mention that the fix is in 3.9.2
– https://wpscan.com/vulnerability/0ecaeb97-4f67-4e79-bea8-9c9a6ab7add3/
– https://vdp.patchstack.com/database/wordpress/plugin/td-cloud-library/vulnerability/wordpress-tagdiv-cloud-library-plugin-3-9-cross-site-scripting-xss-vulnerability
– https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/td-cloud-library/tagdiv-cloud-library-39-authenticated-contributor-stored-cross-site-scripting
Another solution is to manually change the plugin version – https://i.imgur.com/2V5Okji.png
We updated the tagDiv Cloud Library plugin to version 3.9.2, which includes the fix for the XSS vulnerability.
However, all security scanners (Wordfence, WPScan, Patchstack, etc.) are still showing the same vulnerability.
Could you please let us know what we should do in this case, or if there are any additional steps needed to clear these warnings?
Hi yassinee,
We have done all the steps that we can to (Wordfence, WPScan, Patchstack, etc.), and they have updated the fix according to the links above. Now, some plugins in the free version will not show that the problem is resolved until 30 days after, because they only update their resources related to vulnerabilities once every 30 days.
What else can be done is according to the suggestion to change the plugin version from 3.9.2 to 3.9.3 (or whatever version you want that is higher than the current one). If you want, we can do it for you. For this, contact us via email at contact@tagdiv.com and provide wp-admin access.
Thank you!
Hi,
More than 30 days have passed since the tagDiv Cloud Library plugin was flagged by Wordfence and similar scanners as vulnerable and the warning is still present in the latest database of threats update.
Maybe it could be a good idea to release a new version of the plugin?
Thank you,
Hi,
There was no new version for the plugin because we received the confirmation that the problem is resolved in the tagDiv Cloud Library version 3.9.2, and the message continues to pop up because of the way the version is displayed for our theme plugin, the answer was that it should be only Version 3.9.3 and our plugin displays Version 3.9.3| built on 22.10.2025 10:59
But now that we’ve mentioned it, our developers are already working on an update to the theme, but it will most likely be released in January.
I appreciate your understanding!