PLUGIN SECURITY
Is Td Composer safe?
An All in One GDPR Plugin for everything! Responsive Cookie Notice - Imprint & Privacy Policy Generator - integrate external Services GDPR complia …
What this plugin does
- Slug:
td-composer - Author: mlfactory
- 10000+ active installs
- 80/100 rating (165 reviews on wordpress.org)
- 366983 all-time downloads
- On WordPress.org since 2018-06-12
cookiecookie noticedatenschutzdsgvoGDPR
Maintenance status
- Latest known version: 5.0
- Last updated: 2026-04-11 8:25am GMT
- Tested up to WordPress: 6.9.7
- Requires PHP: 5.6+
Known vulnerabilities
23 known CVEs on file for Td Composer.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-12561 | tagDiv Composer [td-composer] <= 5.4.5 (unfixed) | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 5.4.5 | 5.4.5 | 2026-08-25 | ⚠ update needed |
| CVE-2026-57734 | tagDiv Composer [td-composer] < 5.4.6 | — | High 7.1 | < 5.4.6 | 5.4.6 | 2026-07-06 | ⚠ update needed |
| CVE-2025-50001 | tagDiv Composer [td-composer] < 5.4.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 5.4.3 | 5.4.3 | 2026-03-10 | ⚠ update needed |
| CVE-2026-39712 | tagDiv Composer [td-composer] < 5.4.5 | — | Medium 5.3 | < 5.4.5 | 5.4.5 | 2026-03-02 | ⚠ update needed |
| CVE-2026-39692 | tagDiv Composer [td-composer] < 5.4.5 | — | Medium 6.5 | < 5.4.5 | 5.4.5 | 2026-02-24 | ⚠ update needed |
| CVE-2025-50005 | tagDiv Composer [td-composer] < 5.4.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 5.4.3 | 5.4.3 | 2026-01-08 | ⚠ update needed |
| CVE-2025-62030 | tagDiv Composer [td-composer] < 5.4.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 5.4.2 | 5.4.2 | 2025-10-16 | ⚠ update needed |
| CVE-2025-62031 | tagDiv Composer [td-composer] < 5.4.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 5.4.2 | 5.4.2 | 2025-10-09 | ⚠ update needed |
+ 19 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-13645 | tagDiv Composer [td-composer] < 5.4 | Improper Control of Generation of Code ('Code Injection') | Critical 9.8 | < 5.4 | 5.4 | 2025-04-03 | ⚠ update needed |
| CVE-2024-5212 | tagDiv Composer [td-composer] < 5.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 5.1 | 5.1 | 2024-08-30 | ⚠ update needed |
| CVE-2024-3886 | tagDiv Composer [td-composer] < 5.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 5.1 | 5.1 | 2024-08-30 | ⚠ update needed |
| CVE-2024-3888 | tagDiv Composer [td-composer] < 4.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 4.9 | 4.9 | 2024-06-03 | ✓ fixed in latest |
| CVE-2024-3814 | tagDiv Composer [td-composer] < 4.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 4.9 | 4.9 | 2024-04-18 | ✓ fixed in latest |
| CVE-2024-3813 | tagDiv Composer [td-composer] < 4.9 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | High 8.8 | < 4.9 | 4.9 | 2024-04-18 | ✓ fixed in latest |
| CVE-2023-3169 | tagDiv Composer [td-composer] < 4.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 4.2 | 4.2 | 2023-08-17 | ✓ fixed in latest |
| CVE-2023-3170 | tagDiv Composer [td-composer] < 4.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 4.2 | 4.2 | 2023-08-17 | ✓ fixed in latest |
| CVE-2023-39166 | tagDiv Composer [td-composer] < 4.4 | Cross-Site Request Forgery (CSRF) | High 7.1 | < 4.4 | 4.4 | 2023-07-25 | ✓ fixed in latest |
| CVE-2023-1596 | tagDiv Composer [td-composer] < 4.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 4.0 | 4.0 | 2023-04-17 | ✓ fixed in latest |
| CVE-2022-3477 | tagDiv Composer [td-composer] < 3.5 | Improper Authentication | Critical 9.8 | < 3.5 | 3.5 | 2022-10-24 | ✓ fixed in latest |
| — | tagDiv Composer [td-composer] < 5.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 5.4 | 5.4 | 0000-00-00 | ⚠ update needed |
| — | tagDiv Composer [td-composer] < 5.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 5.4 | 5.4 | 0000-00-00 | ⚠ update needed |
| — | tagDiv Composer [td-composer] < 5.4.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.4.1 | 5.4.1 | 0000-00-00 | ⚠ update needed |
| — | tagDiv Composer [td-composer] < 5.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 5.4 | 5.4 | 0000-00-00 | ⚠ update needed |
| CVE-2025-2804 | tagDiv Composer < 5.4 - Reflected Cross-Site Scripting via 'account_id' and 'account_username' | — | Unknown | < 5.4 | 5.4 | — | ⚠ update needed |
| CVE-2025-1705 | tagDiv Composer < 5.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting | — | Unknown | < 5.4 | 5.4 | — | ⚠ update needed |
| CVE-2025-3510 | tagDiv Composer < 5.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes | — | Unknown | < 5.4.1 | 5.4.1 | — | ⚠ update needed |
| CVE-2025-2806 | tagDiv Composer < 5.4 - Reflected Cross-Site Scripting via 'data' | — | Unknown | < 5.4 | 5.4 | — | ⚠ update needed |
How to fix it
Keep Td Composer updated — 5.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- CookieYes – Cookie Banner for Cookie Consent (Easy to setup GDPR/CCPA Compliant Cookie Notice) — 1000000+ active installs — 96/100 (3230) — max PHP 8.4
- Complianz GDPR/CCPA Cookie Consent Banner — 1000000+ active installs — 94/100 (1656) — max PHP 8.4
- CookieAdmin – Cookie Consent Banner — 400000+ active installs — 100/100 (4) — max PHP 8.4
- WPConsent – Cookie Banner & Cookie Consent for Privacy Compliance (GDPR / CCPA / EU Compliance Cookie Notice) — 200000+ active installs — 96/100 (82)
- Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More — 100000+ active installs — 96/100 (317) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.