Extension WordPress
Vulnérabilités tagDiv Opt-In Builder
Cette page rassemble les failles publiées pour tagDiv Opt-In Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de tagDiv Opt-In Builder
5 fiches
tagDiv Opt-In Builder <= 1.7.4 – Unauthenticated Stored Cross-Site Scripting
The tagDiv Opt-In Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-1.7.4
Non indiqué
06/07/2026
tagDiv Opt-In Builder <= 1.7.3 – Reflected Cross-Site Scripting
The tagDiv Opt-In Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-1.7.3
1.7.4
16/03/2026
tagDiv Opt-In Builder <= 1.7 – Authenticated (Subscriber+) SQL Injection via subscriptionCouponId Parameter
The tagDiv Opt-In Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘subscriptionCouponId’ parameter in all versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient…
*-1.7
1.7.1
29/04/2025
tagDiv Opt-In Builder <= 1.4.4 – Authenticated (Admin+) SQL Injection
The tagDiv Opt-In Builder plugin is vulnerable to Blind SQL Injection via the 'subscriptionCouponId' parameter via the 'create_stripe_subscription' REST API endpoint in versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and…
*-1.4.4
1.5
16/08/2024
tagDiv Opt-In Builder <= 1.4.4 – Authenticated (Admin+) SQL Injection
The tagDiv Opt-In Builder plugin is vulnerable to Blind SQL Injection via the 'couponId' parameter of the 'recreate_stripe_subscription' REST API endpoint in versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and…
*-1.4.4
1.5
16/08/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.