Impact
An improper neutralization of input during web page generation allows attackers to inject malicious scripts into pages served by the tagDiv Cloud Library plugin. The vulnerability is a DOM‑based cross‑site scripting flaw that can enable an attacker to run arbitrary JavaScript in the context of the victim’s browser, potentially stealing session data, defacing content, or redirecting users. The weakness originates from the plugin’s inadequate sanitization of user input as described by CWE‑79.
Affected Systems
The tagDiv Cloud Library plugin for WordPress versions older than 3.9.2 is impacted. This includes all installations using the plugin before the 3.9.2 update, regardless of site configuration.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate impact. The EPSS score of less than 1% suggests a low probability of exploitation at large scale, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the change is reachable from a user‑controlled URL or input field, so an attacker can deliver a crafted payload remotely. While direct authentication is not required, the impact is confined to the browser context of the victim.
OpenCVE Enrichment