Input validation vulnerability in tagDiv Composer 4.8

The plugin called “tagDiv Composer” for WordPress has a security issue where malicious code can be inserted through a button feature. This can happen in all versions up to 4.8 if the user-provided information is not properly checked and sanitized. This means that someone with at least contributor-level access can add harmful code to a page that will run whenever someone views that page. It’s important to note that this problem is only found in the tagDiv Newspaper theme, and not in other themes like NewsMag.

Detected in:

tagDiv Composer fixed vulnerable versions: >= * <= 4.8

This information is sourced from An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.