CVE-2024-5212
The tagDiv Composer plugin for WordPress contains a reflected cross-site scripting vulnerability in versions 5.0 and earlier, affecting the on_ajax_register_forum_user function through the 'envato_code[]' parameter. The flaw stems from inadequate sanitization of user input and insufficient escaping of output, allowing unauthenticated attackers to inject malicious scripts. An attacker could exploit this by crafting a malicious link that, when clicked by a user, would execute arbitrary JavaScript in the user's browser.
Based on public CVE data (MITRE/NVD).