CVE-2024-3886: tagDiv Composer <= 5.0 - Reflected Cross-Site Scripting via envato_code[]
The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envatocode[]’ parameter in all versions up to, and including, 5.0 due to insufficient input sanitization and output escaping within the onajaxcheckenvatocode function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3886?
CVE-2024-3886 is classified as a medium severity vulnerability due to the potential for reflected cross-site scripting attacks.
How do I fix CVE-2024-3886?
To fix CVE-2024-3886, update the Tagdiv Composer plugin to version 5.1 or higher where the vulnerability has been patched.
What software is affected by CVE-2024-3886?
CVE-2024-3886 affects all versions of the Tagdiv Composer plugin for WordPress up to and including version 5.0.
What does CVE-2024-3886 exploit?
CVE-2024-3886 exploits insufficient input sanitization and output escaping in the on_ajax_check_envato_code function via the 'envato_code[]' parameter.
Who should be concerned about CVE-2024-3886?
Website administrators using the Tagdiv Composer plugin on their WordPress sites should be concerned about CVE-2024-3886 and take appropriate action to mitigate the risks.