CVE · High

CVE-2023-39166 — tagDiv Composer [td-composer] < 4.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-39166 tagDiv Composer [td-composer] < 4.4 Cross-Site Request Forgery (CSRF) High 7.1 < 4.4 4.4 2023-07-25

CVE-2023-39166

The tagDiv Composer plugin for WordPress through version 4.3 contains a Cross-Site Request Forgery vulnerability caused by inadequate nonce verification in certain functions. An attacker could exploit this flaw by crafting a malicious request and inducing a site administrator to click a link, allowing the injection of harmful scripts into website pages. The vulnerability affects all versions before 4.4.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.