tagDiv Composer
cpe:2.3:a:tagdiv:tagdiv_composer:*:*:*:*:wordpress:*:*
- <= 5.3
A reflected cross-site scripting vulnerability has been identified in the tagDiv Composer plugin for WordPress, which is utilized by the Newspaper theme. This vulnerability exists in all versions through 5.3 and arises from inadequate input sanitization and output escaping. As a result, unauthenticated attackers can inject arbitrary web scripts into pages, which may be executed if a user is tricked into interacting with a malicious link.
Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Users are advised to update the tagDiv Composer plugin to version 5.4 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.