Tagdiv

Composer

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.53%
  • Veröffentlicht 08.05.2025 11:23:40
  • Zuletzt bearbeitet 04.06.2025 22:53:20

The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting via the ‘data’ parameter in all versions up to, and including, 5.3 due to insufficient input sanitization and output escaping. This...

  • EPSS 0.15%
  • Veröffentlicht 02.05.2025 03:21:18
  • Zuletzt bearbeitet 06.05.2025 15:19:30

The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all versions up to, and including, 5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes...

  • EPSS 2.23%
  • Veröffentlicht 04.04.2025 05:22:44
  • Zuletzt bearbeitet 07.04.2025 14:18:15

The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including, 5.3 via module parameter. This makes it possible for unauthenticated attackers to Instantiate a PHP Object. No known POP chain is...

  • EPSS 0.25%
  • Veröffentlicht 28.03.2025 08:23:44
  • Zuletzt bearbeitet 28.03.2025 18:11:40

The tagDiv Composer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3. This is due to missing or incorrect nonce validation within the td_ajax_get_views AJAX action. This makes it possible for ...

  • EPSS 0.48%
  • Veröffentlicht 28.03.2025 05:23:44
  • Zuletzt bearbeitet 28.03.2025 18:11:40

The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting via the 'account_id' and 'account_username' parameters in all versions up to, and including, 5.3 due to insufficient input sanitiza...

  • EPSS 0.31%
  • Veröffentlicht 04.06.2024 05:15:49
  • Zuletzt bearbeitet 21.11.2024 09:30:38

The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button shortcode in all versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on user supplied attributes. ...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 15.05.2023 13:15:10
  • Zuletzt bearbeitet 24.01.2025 21:15:09

The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin