tagDiv Cloud Library <= 3.9.5 - Unauthenticated Stored Cross-Site Scripting
high
The tagDiv Cloud Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.9.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user a...
- CVSS:
- 7.2
- Affected:
- up to 3.9.5
- Fixed in:
- 3.9.6
- Disclosed:
- Jul 6, 2026
CVE-2026-57733 on NVD →
tagDiv Cloud Library < 3.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The tagDiv Cloud Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and excluding, 3.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in p...
- CVSS:
- 6.4
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.2
- Disclosed:
- Oct 16, 2025
CVE-2025-62032 on NVD →
tagDiv Cloud Library [td-cloud-library] < 2.7
unknown
[en] The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the...
- Affected:
- up to 2.7
- Fixed in:
- 2.7
- Disclosed:
- Jul 10, 2023
CVE-2023-1597 on NVD →
tagDiv Cloud Library < 2.7 - Missing Authorization to Arbitrary User Metadata Update
critical
The tagDiv Cloud Library plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tdb_user_form_on_submit() function called via an AJAX action in versions prior to 2.7. This makes it possible for unauthenticated attackers to modify arbitrary user metadata and gain...
- CVSS:
- 9.8
- Affected:
- up to 2.7
- Fixed in:
- 2.7
- Disclosed:
- Jun 19, 2023
CVE-2023-1597 on NVD →
tagDiv Cloud Library [td-cloud-library] < 4.0
unknown
- Affected:
- up to 4.0
- Fixed in:
- 4.0
CVE-2025-62032 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database