Extension WordPress

Vulnérabilités tagDiv Composer

Cette page rassemble les failles publiées pour tagDiv Composer, leurs plages de versions affectées et les correctifs signalés dans la base locale.

22Vulnérabilités
2Critiques
21Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de tagDiv Composer

22 fiches

CVE-2026-39692 Moyenne · 6,4
tagDiv Composer

tagDiv Composer <= 5.4.4 – Authenticated (Contributor+) Stored Cross-Site Scripting

The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…

Versions affectées

*-5.4.4

Correctif

5.4.5

Publication

24/02/2026

CVE-2025-50005 Moyenne · 6,4
tagDiv Composer

tagDiv Composer <= 5.4.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…

Versions affectées

*-5.4.2

Correctif

5.4.3

Publication

08/01/2026

CVE-2025-62030 Moyenne · 6,4
tagDiv Composer

tagDiv Composer <= 5.4.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…

Versions affectées

*-5.4.1

Correctif

5.4.2

Publication

16/10/2025

CVE-2025-3510 Moyenne · 6,4
tagDiv Composer

tagDiv Composer <= 5.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes

The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all versions up to, and including, 5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

Versions affectées

*-5.4

Correctif

5.4.1

Publication

01/05/2025

CVE-2025-2804 Moyenne · 6,1
tagDiv Composer

tagDiv Composer <= 5.3 – Reflected Cross-Site Scripting via 'account_id' and 'account_username'

The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting via the 'account_id' and 'account_username' parameters in all versions up to, and including, 5.3 due to insufficient input sanitization and output…

Versions affectées

*-5.3

Correctif

5.4

Publication

27/03/2025

CVE-2024-3886 Moyenne · 6,1
tagDiv Composer

tagDiv Composer <= 5.0 – Reflected Cross-Site Scripting via envato_code[]

The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and including, 5.0 due to insufficient input sanitization and output escaping within the on_ajax_check_envato_code function. This makes…

Versions affectées

*-5.0

Correctif

5.1

Publication

30/08/2024

CVE-2024-5212 Moyenne · 6,1
tagDiv Composer

tagDiv Composer <= 5.0 – Reflected Cross-Site Scripting via envato_code[]

The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and including, 5.0 due to insufficient input sanitization and output escaping within the on_ajax_register_forum_user function. This makes…

Versions affectées

*-5.0

Correctif

5.1

Publication

30/08/2024

CVE-2024-3813 Élevée · 8,8
tagDiv Composer

tagDiv Composer <= 4.8 – Authenticated (Contributor+) Local File Inclusion via Shortcode

The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8 via the 'td_block_title' shortcode 'block_template_id' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions,…

Versions affectées

*-4.8

Correctif

4.9

Publication

18/04/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités