Impact
The vulnerability is a CWE‑79 Cross‑Site Scripting issue. The tagDiv Composer plugin fails to neutralize user‑supplied input before rendering it back to the browser, allowing malicious scripts to be injected and executed in the context of the victim’s browser. This can lead to client‑side code execution, session hijacking, data theft, or content tampering, posing significant confidentiality, integrity, and availability risks.
Affected Systems
The plugin affected is tagDiv Composer for WordPress, any installation using version 5.4.3 or older. No other products or vendors are listed as impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation is likely to occur via crafted URLs or inputs that are reflected back in the page, requiring only a victim’s browser. Although the threat of widespread attacks is low, the potential damage from successful exploitation warrants prompt mitigation.
OpenCVE Enrichment