Unknown Tagdiv Composer vulnerabilities

3 known vulnerabilities affecting unknown/tagdiv_composer.

Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2023-3170MEDIUMCVSS 4.8fixed in 4.22023-09-11
CVE-2023-3170 [MEDIUM] CWE-79 CVE-2023-3170: The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag th The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not validate and escape some settings, which could allow users with Admin privileges to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
cvelistv5nvd
CVE-2023-3169MEDIUMCVSS 6.1PoCfixed in 4.22023-09-11
CVE-2023-3169 [MEDIUM] CWE-79 CVE-2023-3169: The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag th The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in a REST route and does not validate as well as escape some parameters when outputting them back, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.
cvelistv5nvd
CVE-2023-1596MEDIUMCVSS 6.1fixed in 4.02023-05-15
CVE-2023-1596 [MEDIUM] CWE-79 CVE-2023-1596: The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outp The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
cvelistv5nvd