Impact
The tagDiv Cloud Library plugin for WordPress contains a DOM‑Based Cross‑Site Scripting vulnerability caused by improper neutralization of user‑supplied input during page rendering. The flaw enables an attacker to inject arbitrary client‑side scripts that execute in the browsers of users who view affected pages, potentially compromising information disclosed in that context.
Affected Systems
This flaw affects the tagDiv Cloud Library (td‑cloud‑library) plugin for WordPress through version 3.9.4 and earlier.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating high severity. Its EPSS score is below 1 %, suggesting exploitation is unlikely in the current real‑world environment. The flaw is not listed in the CISA KEV catalog. Likely exploitation requires a user to visit a page generated by the vulnerable plugin; based on the nature of XSS, it is inferred that no special privileges are required. The likely attack vector is DOM‑Based XSS.
OpenCVE Enrichment