CVE · Medium

CVE-2024-5212 — tagDiv Composer [td-composer] < 5.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-5212 tagDiv Composer [td-composer] < 5.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 5.1 5.1 2024-08-30

CVE-2024-5212

The tagDiv Composer plugin for WordPress contains a reflected cross-site scripting vulnerability in versions 5.0 and earlier, affecting the on_ajax_register_forum_user function through the 'envato_code[]' parameter. The flaw stems from inadequate sanitization of user input and insufficient escaping of output, allowing unauthenticated attackers to inject malicious scripts. An attacker could exploit this by crafting a malicious link that, when clicked by a user, would execute arbitrary JavaScript in the user's browser.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.