XSS Vulnerability in tagDiv Composer Plugin by tagDiv
CVE-2026-39712
5.3MEDIUM
What is CVE-2026-39712?
The tagDiv Composer plugin, utilized in WordPress environments, is susceptible to an improper neutralization of script-related HTML tags in web pages. This vulnerability enables attackers to inject malicious code through the plugin, impacting versions from n/a to 5.4.3. Users of the plugin should ensure they are using a patched version to mitigate the risk of code execution vulnerabilities.
Affected Version(s)
tagDiv Composer 0 <= 5.4.3