Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Cloud Library td-cloud-library allows DOM-Based XSS.This issue affects tagDiv Cloud Library: from n/a through <= 3.9.4.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The tagDiv Cloud Library plugin for WordPress contains a DOM‑Based Cross‑Site Scripting vulnerability caused by improper neutralization of user‑supplied input during page rendering. The flaw enables an attacker to inject arbitrary client‑side scripts that execute in the browsers of users who view affected pages, potentially compromising information disclosed in that context.

Affected Systems

This flaw affects the tagDiv Cloud Library (td‑cloud‑library) plugin for WordPress through version 3.9.4 and earlier.

Risk and Exploitability

The vulnerability has a CVSS score of 7.1, indicating high severity. Its EPSS score is below 1 %, suggesting exploitation is unlikely in the current real‑world environment. The flaw is not listed in the CISA KEV catalog. Likely exploitation requires a user to visit a page generated by the vulnerable plugin; based on the nature of XSS, it is inferred that no special privileges are required. The likely attack vector is DOM‑Based XSS.

Generated by OpenCVE AI on August 1, 2026 at 10:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the tagDiv Cloud Library plugin to version 3.9.5 or later.
  • If an update cannot be applied immediately, disable or uninstall the plugin to prevent the vulnerable code from executing.
  • Apply a Content Security Policy that blocks inline scripts to mitigate potential injection until a patch is available.

Generated by OpenCVE AI on August 1, 2026 at 10:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Cloud Library td-cloud-library allows DOM-Based XSS.This issue affects tagDiv Cloud Library: from n/a through <= 3.9.4.
Title WordPress tagDiv Cloud Library plugin <= 3.9.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T14:38:38.728Z

Reserved: 2026-06-25T08:04:20.944Z

Link: CVE-2026-57733

cve-icon Vulnrichment

Updated: 2026-07-13T13:54:35.309Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')