PatchSiren cyber security CVE debrief
CVE-2026-12561 tagDiv CVE debrief
The tagDiv Composer plugin for WordPress has a Stored Cross-Site Scripting vulnerability via the vc_raw_html shortcode in all versions up to and including 5.4.5. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts in pages, which execute when a user accesses an injected page. The vulnerability exists due to insufficient input sanitization and output escaping in the vc_raw_html::render() method. The plugin's failure to properly sanitize and escape base64-decoded shortcode content enables the injection of malicious scripts. WordPress administrators, security teams, and users with Contributor-level access and above,
- Vendor
- tagDiv
- Product
- tagDiv Composer
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-09-28
Who should care
WordPress administrators, security teams, and users with Contributor-level access and above should assess exposure and prioritize remediation. Affected operator, platform, vulnerability-management, and security-team impact must be evaluated to ensure proper mitigation and protection of sensitive data.
Why it matters
CVE-2026-12561 is a Stored Cross-Site Scripting vulnerability in the tagDiv Composer plugin for WordPress. Authenticated attackers with Contributor-level access and above can inject arbitrary web scripts in pages, which execute when a user accesses an injected page. WordPress administrators and security teams should assess exposure and prioritize remediation.
- Authenticated attackers can inject arbitrary web scripts in pages
- Injected scripts execute when a user accesses an injected page
- Contributor-level access and above is required for exploitation
- Remediation requires updating plugin versions and restricting access
Technical summary
The vulnerability exists in the vc_raw_html shortcode of the tagDiv Composer plugin for WordPress. Insufficient input sanitization and output escaping in the vc_raw_html::render() method allow base64-decoded shortcode content to be concatenated directly into the page HTML. This enables authenticated attackers with Contributor-level access and above to inject arbitrary web scripts in pages. The vulnerability is exacerbated by WordPress's save-time wp_kses_post() filter not decoding base64-encoded payloads, allowing dangerous tags to survive into post_content and be emitted unescaped at render time.
Defensive priority
Remediate vulnerable plugin versions, restrict Contributor-level access, monitor for suspicious page previews
Recommended defensive actions
- Update tagDiv Composer plugin to a version beyond 5.4.5
- Restrict Contributor-level access to trusted users
- Monitor for suspicious page previews and injected scripts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability exists due to insufficient input sanitization and output escaping in the vc_raw_html::render() method. WordPress's save-time wp_kses_post() filter does not decode base64-encoded payloads, allowing dangerous tags to survive into post_content and be emitted unescaped at render time.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-12561 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-12561
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-12561 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12561
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://tagdiv.com/tagdiv-composer-page-builder-basics/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.