PatchSiren

tagDiv CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH tagDiv CVE published 2026-07-13

CVE-2026-57734

CVE-2026-57734 is a Cross-site Scripting vulnerability in tagDiv Composer, a WordPress plugin used for creating and managing content. The vulnerability is caused by improper neutralization of input during web page generation, allowing attackers to inject malicious scripts. The CVE record was published on 2026-07-13T10:16:39.997Z and has not been modified since then. The NVD entry is currently 7.1 HIGH, in [truncated]

HIGH tagDiv CVE published 2026-07-13

CVE-2026-57733

A Cross-site Scripting vulnerability was found in tagDiv Cloud Library, a popular WordPress plugin used for creating and managing cloud-based libraries. This issue allows attackers to inject malicious scripts into web pages, potentially leading to unauthorized actions or data theft. The vulnerability, tracked as CVE-2026-57733, affects tagDiv Cloud Library versions from n/a through <= 3.9.4. Administrator [truncated]

HIGH tagDiv CVE published 2026-07-13

CVE-2026-57732

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-13T10:16:39.767Z and has not been modified since then. The vulnerability affects tagDiv Opt-In Builder plugin, allowing DOM-Based XSS attacks. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Users of tagDiv Opt-In Builder plugin versions up to 1.7.4 should apply patches [truncated]

MEDIUM tagDiv CVE published 2026-04-08

CVE-2026-39712

CVE-2026-39712 is a MEDIUM severity vulnerability in tagDiv Composer, a WordPress plugin. The issue is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability, which allows Code Injection. This type of vulnerability can lead to malicious actions, potentially impacting users of the affected plugin. The CVE record was published on 2026-04-08T09:16:44.130Z and was last [truncated]

MEDIUM tagDiv CVE published 2026-04-08

CVE-2026-39692

CVE-2026-39692 is a Stored Cross-site Scripting (XSS) vulnerability in the tagDiv Composer plugin, affecting versions up to and including 5.4.3. This issue allows authenticated attackers with low privileges to inject malicious scripts into web pages, potentially leading to unauthorized actions and data breaches. The vulnerability's CVSS score is 6.5, indicating a medium severity level. Administrators shou [truncated]