Executive brief
tagDiv Composer is a WordPress page builder plugin used to create and design website pages visually. The plugin's vc_raw_html shortcode contains a vulnerability that allows authenticated contributors and above to inject malicious JavaScript code into pages. When other users (such as editors or administrators) view or preview these pages, the injected code executes in their browser, potentially compromising their accounts or stealing sensitive data.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the vc_raw_html shortcode's render() method. The root cause is insufficient input sanitization and output escaping: the method base64-decodes shortcode content and concatenates it directly into page HTML. WordPress's wp_kses_post() filter runs at save time but only sees the inert base64-encoded text inside the shortcode bracket, allowing dangerous HTML and JavaScript tags to bypass validation. At render time, the decoded payload is output unescaped, executing arbitrary scripts. The vulnerability requires authentication (Contributor level or above) but affects any user viewing the injected page. No patch information is currently available.
Affected products
- tagDiv Composer up to and including 5.4.5
Timeline
- 2026-08-25: disclosed