Executive brief
tagDiv Opt-In Builder is a WordPress plugin used to create subscription and lead-generation forms. A security flaw in this plugin allows attackers to inject malicious scripts into the web pages seen by other users. If a user clicks a specially crafted link, an attacker could potentially steal session information, redirect visitors to malicious sites, or perform actions on behalf of the user.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the tagDiv Opt-In Builder (td-subscription) plugin for WordPress, affecting versions up to and including 1.7.4. The flaw stems from improper neutralization of user-supplied input during web page generation, specifically within the td-subscription component. An unauthenticated attacker can exploit this by tricking a user into interacting with a malicious link or crafted page, leading to the execution of arbitrary JavaScript in the victim's browser session. As of the advisory date, no official patch has been released by the vendor.
Affected products
- tagDiv tagDiv Opt-In Builder (td-subscription) n/a through 1.7.4
Timeline
- 2026-04-26: disclosed: Reported by Bonds to Patchstack
- 2026-07-06: advisory: Initial advisory published by Patchstack
- 2026-07-13: advisory: CVE published to NVD dataset