Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation (XSS) in the tagDiv Composer plugin. It permits the injection of scripts that will execute in the browsers of visitors who view affected pages.
Affected Systems
WordPress sites that use tagDiv Composer plugin version 5.4.1 or earlier are affected. All installations that have not applied the latest patch, including version 5.4.1, remain vulnerable.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests that the likelihood of exploitation in the wild is low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector could involve injecting malicious code through the plugin’s content editing interface, which is then rendered to visitors’ browsers.
OpenCVE Enrichment