CVE-2025-50001: WordPress tagDiv Composer plugin <= 5.4.2 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50001?
CVE-2025-50001 has been classified as a high severity reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-50001?
To fix CVE-2025-50001, update the tagDiv Composer plugin to a version newer than 5.4.2.
Who is affected by CVE-2025-50001?
CVE-2025-50001 affects users of the tagDiv Composer plugin on WordPress installations running version 5.4.2 or older.
What type of attack can CVE-2025-50001 enable?
CVE-2025-50001 can enable attackers to execute arbitrary JavaScript in the browser of users visiting compromised pages.
Is there a workaround for CVE-2025-50001?
While the best practice is to update the plugin, users may also implement input validation to mitigate the risk of XSS until they can update.