plugin

Td Cloud Library Vulnerabilities

5 known security issues reported for the Td Cloud Library WordPress plugin. Most recent disclosed Jul 6, 2026.

1 critical 1 high 1 medium

Running Td Cloud Library on your site? Check whether your installed version is affected.

Scan your site free

tagDiv Cloud Library <= 3.9.5 - Unauthenticated Stored Cross-Site Scripting

high

The tagDiv Cloud Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.9.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user a...

CVSS:
7.2
Affected:
up to 3.9.5
Fixed in:
3.9.6
Disclosed:
Jul 6, 2026

CVE-2026-57733 on NVD →

tagDiv Cloud Library < 3.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The tagDiv Cloud Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and excluding, 3.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in p...

CVSS:
6.4
Affected:
up to 3.9.2
Fixed in:
3.9.2
Disclosed:
Oct 16, 2025

CVE-2025-62032 on NVD →

tagDiv Cloud Library [td-cloud-library] < 2.7

unknown

[en] The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the...

Affected:
up to 2.7
Fixed in:
2.7
Disclosed:
Jul 10, 2023

CVE-2023-1597 on NVD →

tagDiv Cloud Library < 2.7 - Missing Authorization to Arbitrary User Metadata Update

critical

The tagDiv Cloud Library plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tdb_user_form_on_submit() function called via an AJAX action in versions prior to 2.7. This makes it possible for unauthenticated attackers to modify arbitrary user metadata and gain...

CVSS:
9.8
Affected:
up to 2.7
Fixed in:
2.7
Disclosed:
Jun 19, 2023

CVE-2023-1597 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database