Junglewise Threat Intelligence

CVE-2026-57733: tagDiv Cloud Library DOM-based XSS in td-cloud-library

CVE-2026-57733 · Severity: high · CVSS 7.1 · Published 2026-07-13

Vendors: tagDiv.

Executive brief

The tagDiv Cloud Library plugin for WordPress, which provides cloud-based templates and design elements for websites, is vulnerable to a security flaw. An attacker could trick a site administrator or visitor into clicking a malicious link, allowing the attacker to run unauthorized scripts in their browser. This could lead to unauthorized actions being performed on the site, theft of session information, or redirection to malicious websites.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the tagDiv Cloud Library (td-cloud-library) plugin for WordPress due to improper neutralization of input during web page generation. The flaw allows unauthenticated attackers to inject malicious scripts into the Document Object Model (DOM) environment. Successful exploitation requires a user to interact with a specially crafted link or page. Once executed, the script runs within the context of the victim's browser session, potentially allowing for session hijacking or unauthorized administrative actions. As of the advisory date, no official patch has been released by the vendor.

Affected products

  • tagDiv tagDiv Cloud Library (td-cloud-library) <= 3.9.4

Timeline

  • 2026-04-26: disclosed: Vulnerability reported by researcher Bonds
  • 2026-07-06: advisory: Patchstack published the vulnerability details
  • 2026-07-13: advisory: CVE published to NVD dataset

References