Executive brief
tagDiv Composer is a popular page builder plugin for WordPress websites. A vulnerability in this plugin allows unauthorized individuals to inject malicious code or content into a website's pages. This could lead to the creation of phishing pages, unauthorized content modification, or the redirection of visitors to malicious sites, potentially damaging the site's reputation and user trust.
Technical details
A vulnerability exists in the tagDiv Composer (td-composer) plugin for WordPress through version 5.4.4 due to improper neutralization of script-related HTML tags. This flaw allows an unauthenticated remote attacker to perform content injection and arbitrary shortcode execution. By sending a specially crafted request, an attacker can inject malicious scripts or content into the web pages served by the plugin. The issue is classified as CWE-80 (Improper Neutralization of Script-Related HTML Tags in a Web Page). A patch is available in version 5.4.5.
Affected products
- tagDiv tagDiv Composer <= 5.4.4
Timeline
- 2026-01-31: other: Vulnerability reported by researcher Bonds
- 2026-03-02: disclosed: Initial disclosure by Patchstack
- 2026-03-02: patched: Patch released in version 5.4.5
- 2026-04-08: advisory: CVE published to NVD