Vulnerabilities
Vulnerable Software
Tagdiv:  Security Vulnerabilities
The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the blog.
CVSS Score
8.8
EPSS Score
0.003
Published
2023-07-10
The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVSS Score
6.1
EPSS Score
0.001
Published
2023-05-15
The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting
CVSS Score
6.1
EPSS Score
0.002
Published
2022-10-31
The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting.
CVSS Score
6.1
EPSS Score
0.248
Published
2022-10-31
The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.
CVSS Score
6.1
EPSS Score
0.018
Published
2021-08-09
An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call.
CVSS Score
6.1
EPSS Score
0.01
Published
2021-07-19
The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
CVSS Score
9.8
EPSS Score
0.043
Published
2019-09-16
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
CVSS Score
9.8
EPSS Score
0.011
Published
2019-09-16


Contact Us

Shodan ® - All rights reserved