Vulnerable Plugin: td-cloud-library (version 3.9.2 | built on 22.10.2025 10:59)

Posted in: Newspaper
Post count: 23

WordPress Plugin Vulnerabilities
tagDiv Cloud Library < 4.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
Description
The tagDiv Cloud Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Affects Plugins
Plugin icon
td-cloud-library
Fixed in 4.0

https://wpscan.com/vulnerability/0ecaeb97-4f67-4e79-bea8-9c9a6ab7add3/

Post count: 8

WPScan references Wordfence.
Wordfence says 3.9 is bad, 4.0 is fixed, references Patchstack.
Patchstack says 3.9.1 is bad, 3.9.2 is the fixed version.

Same CVE.

One of them is right!

Post count: 3

I am getting the same issue. Ran this past the tech support and awaiting a response.

Post count: 3

Wordpress (via jetpack) is giving the error message so anyone who uses Jetpack will see the vulnerability. We need another update!

Post count: 35449

Hi,

The version passed was incorrect. Patchstack confirmed that Newspaper v12.7.3 and tabDiv Cloud Library v3.9.2 and confirmed that it is fixed.
The fix is in 3.9.2 https://patchstack.com/database/wordpress/plugin/td-cloud-library https://patchstack.com/database/wordpress/plugin/td-cloud-library/vulnerability/wordpress-tagdiv-cloud-library-plugin-3-9-cross-site-scripting-xss-vulnerability

Thank you!

Viewing 5 posts - 1 through 5 (of 5 total)
You must be logged in to reply to this topic.