CVE-2024-5212: tagDiv Composer <= 5.0 - Reflected Cross-Site Scripting via envato_code[]
The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envatocode[]’ parameter in all versions up to, and including, 5.0 due to insufficient input sanitization and output escaping within the onajaxregisterforumuser function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5212?
CVE-2024-5212 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2024-5212?
To fix CVE-2024-5212, update the Tagdiv Composer plugin to version 5.1 or later.
Which versions of Tagdiv Composer are affected by CVE-2024-5212?
CVE-2024-5212 affects all versions of the Tagdiv Composer plugin up to and including version 5.0.
What type of vulnerability is CVE-2024-5212?
CVE-2024-5212 is a Reflected Cross-Site Scripting (XSS) vulnerability.
What component of the Tagdiv Composer plugin is vulnerable in CVE-2024-5212?
The vulnerability in CVE-2024-5212 exists in the on_ajax_register_forum_user function due to insufficient input sanitization and output escaping.