First published: Mon Jul 19 2021(Updated: )
An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tagdiv Newspaper | =10.3.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-3135.
The affected software is the tagDiv Newspaper theme version 10.3.9.1 for WordPress.
The severity of CVE-2021-3135 is medium with a CVSS score of 6.1.
An attacker can exploit this vulnerability by performing cross-site scripting (XSS) attacks via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call.
Yes, you can find more information about the tagDiv Newspaper theme at the following references: [https://tagdiv.com/newspaper/](https://tagdiv.com/newspaper/) and [https://themeforest.net/item/newspaper/5489609](https://themeforest.net/item/newspaper/5489609).