Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.3.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a CWE‑79 Cross‑Site Scripting issue. The tagDiv Composer plugin fails to neutralize user‑supplied input before rendering it back to the browser, allowing malicious scripts to be injected and executed in the context of the victim’s browser. This can lead to client‑side code execution, session hijacking, data theft, or content tampering, posing significant confidentiality, integrity, and availability risks.

Affected Systems

The plugin affected is tagDiv Composer for WordPress, any installation using version 5.4.3 or older. No other products or vendors are listed as impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation is likely to occur via crafted URLs or inputs that are reflected back in the page, requiring only a victim’s browser. Although the threat of widespread attacks is low, the potential damage from successful exploitation warrants prompt mitigation.

Generated by OpenCVE AI on August 1, 2026 at 10:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade tagDiv Composer to a version newer than 5.4.3.
  • If an immediate upgrade is not possible, remove or disable the plugin until a patched version is available.
  • Configure a web application firewall to block payloads containing script tags in HTTP requests that target the plugin’s input fields.

Generated by OpenCVE AI on August 1, 2026 at 10:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Tagdiv
Tagdiv tagdiv Composer
Wordpress
Wordpress wordpress
Vendors & Products Tagdiv
Tagdiv tagdiv Composer
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.3.
Title WordPress tagDiv Composer plugin <= 5.4.3 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Tagdiv Tagdiv Composer
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:30:17.161Z

Reserved: 2026-06-25T08:04:20.944Z

Link: CVE-2026-57734

cve-icon Vulnrichment

Updated: 2026-07-13T13:30:13.551Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')