Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows DOM-Based XSS.This issue affects tagDiv Opt-In Builder: from n/a through <= 1.7.4.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a DOM‑Based XSS that occurs when the plugin fails to neutralize user supplied data before rendering it on a web page. An attacker can construct malicious input that is then displayed to a victim browser, enabling the execution of arbitrary scripts. This can be used for defacement, cookie theft, or other client‑side attacks. No additional impacts beyond script execution are documented in the description.

Affected Systems

The WordPress plugin tagDiv Opt‑In Builder, versions up to and including 1.7.4, is affected. No other products or platforms are listed as impacted by this vulnerability.

Risk and Exploitability

The CVSS score of 7.1 reflects a high severity for the DOM‑Based XSS flaw. The EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker is likely to deliver malicious input through the plugin’s forms or configuration fields, which is then rendered to any user that views the affected page.

Generated by OpenCVE AI on July 29, 2026 at 07:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade tagDiv Opt‑In Builder to a version newer than 1.7.4.
  • If an upgrade is not feasible immediately, disable the plugin on publicly accessible pages or limit its use to non‑critical administrative areas to prevent exposure to untrusted input.
  • Implement a strict Content Security Policy that blocks execution of scripts from untrusted sources to reduce the impact of any remaining reflected XSS vectors.
  • Add a Web Application Firewall rule or input‑filtering mechanism that detects and blocks common XSS payloads targeting the plugin’s input fields.

Generated by OpenCVE AI on July 29, 2026 at 07:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows DOM-Based XSS.This issue affects tagDiv Opt-In Builder: from n/a through <= 1.7.4.
Title WordPress tagDiv Opt-In Builder plugin <= 1.7.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:38:11.765Z

Reserved: 2026-06-25T08:04:20.944Z

Link: CVE-2026-57732

cve-icon Vulnrichment

Updated: 2026-07-13T13:38:07.863Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T08:00:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')