CVE-2026-39712
tagDiv Composer
Minimum safe version
5.4.3
Update to 5.4.3 or later to address 19 fixable vulnerabilities
CVE-2026-39692
CVE-2025-50001
CVE-2025-50005
CVE-2025-62031
CVE-2025-62030
tagDiv Composer <= 5.3 - Reflected Cross-Site Scripting via 'data'
tagDiv Composer <= 5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes
CVE-2024-13645
tagDiv Composer <= 5.3 - Reflected Cross-Site Scripting via 'account_id' and 'account_username'
tagDiv Composer <= 5.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting
WordPress tagDiv Composer Plugin <= 5.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-5212
CVE-2024-3813
CVE-2024-3814
CVE-2024-3888
CVE-2023-3170
CVE-2023-3169
CVE-2023-39166
CVE-2023-1596
WordPress tagDiv Composer Plugin < 3.5 is vulnerable to Broken Authentication