Tagdiv Composer vulnerabilities
2 known vulnerabilities affecting tagdiv/composer.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2025-3510MEDIUMCVSS 5.4fixed in 5.4.12025-05-02
CVE-2025-3510 [MEDIUM] CWE-79 CVE-2025-3510: The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple s
The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all versions up to, and including, 5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary w
nvd
CVE-2023-1596MEDIUMCVSS 6.1fixed in 4.02023-05-15
CVE-2023-1596 [MEDIUM] CWE-79 CVE-2023-1596: The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outp
The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
nvd