CVE-2025-62032: WordPress tagDiv Cloud Library plugin < 3.9.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Cloud Library td-cloud-library allows DOM-Based XSS.This issue affects tagDiv Cloud Library: from n/a through < 3.9.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62032?
CVE-2025-62032 is classified as a high severity vulnerability due to its potential for enabling DOM-based cross-site scripting (XSS) attacks.
How do I fix CVE-2025-62032?
To fix CVE-2025-62032, upgrade tagDiv Cloud Library to version 3.9.2 or later.
What versions of tagDiv Cloud Library are affected by CVE-2025-62032?
CVE-2025-62032 affects tagDiv Cloud Library versions prior to 3.9.2.
What kind of vulnerability is CVE-2025-62032?
CVE-2025-62032 is an improper neutralization of input during web page generation vulnerability, specifically allowing cross-site scripting (XSS).
Can CVE-2025-62032 lead to data theft?
Yes, CVE-2025-62032 can lead to data theft as attackers can execute scripts in the context of the user's browser.