CVE-2021-3135: XSS
An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php tdblockid parameter in a tdajaxblock API call.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2021-3135.
What is the affected software?
The affected software is the tagDiv Newspaper theme version 10.3.9.1 for WordPress.
What is the severity of CVE-2021-3135?
The severity of CVE-2021-3135 is medium with a CVSS score of 6.1.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by performing cross-site scripting (XSS) attacks via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call.
Are there any references for this vulnerability?
Yes, you can find more information about the tagDiv Newspaper theme at the following references: [https://tagdiv.com/newspaper/](https://tagdiv.com/newspaper/) and [https://themeforest.net/item/newspaper/5489609](https://themeforest.net/item/newspaper/5489609).