Junglewise Threat Intelligence

CVE-2026-39712: tagDiv Composer content injection in td-composer

CVE-2026-39712 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Technologies: tagDiv Composer. Vendors: tagDiv.

Executive brief

tagDiv Composer is a popular page builder plugin for WordPress websites. A vulnerability in this plugin allows unauthorized individuals to inject malicious code or content into a website's pages. This could lead to the creation of phishing pages, unauthorized content modification, or the redirection of visitors to malicious sites, potentially damaging the site's reputation and user trust.

Technical details

A vulnerability exists in the tagDiv Composer (td-composer) plugin for WordPress through version 5.4.4 due to improper neutralization of script-related HTML tags. This flaw allows an unauthenticated remote attacker to perform content injection and arbitrary shortcode execution. By sending a specially crafted request, an attacker can inject malicious scripts or content into the web pages served by the plugin. The issue is classified as CWE-80 (Improper Neutralization of Script-Related HTML Tags in a Web Page). A patch is available in version 5.4.5.

Affected products

  • tagDiv tagDiv Composer <= 5.4.4

Timeline

  • 2026-01-31: other: Vulnerability reported by researcher Bonds
  • 2026-03-02: disclosed: Initial disclosure by Patchstack
  • 2026-03-02: patched: Patch released in version 5.4.5
  • 2026-04-08: advisory: CVE published to NVD

References

Related threats