Tagdiv is a modestly represented vendor of WordPress themes and plugins—primarily its Composer and Newspaper product lines—that serve as content-management and publishing frameworks for news and media websites. Vulnerabilities affecting the vendor skew toward serious outcomes, frequently acquire public exploit code, and recur through web-application weakness classes including cross-site scripting, cross-site request forgery, PHP remote file inclusion, and improper privilege management that are characteristic of extensible WordPress ecosystem products. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tagdiv over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10972CRITICAL The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel. | Sep 16, 2019 | 9.8 | 43 | NO | YES |
CVE-2022-2627MEDIUM The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting | Oct 31, 2022 | 6.1 | 32 | NO | YES |
CVE-2026-57734HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tag | Jul 13, 2026 | 7.1 | 31 | NO | NO |
CVE-2023-3169MEDIUM The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in a REST route and does not valid | Sep 11, 2023 | 6.1 | 31 | NO | YES |
CVE-2024-13645CRITICAL The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including, 5.3 via module parameter. This makes it possible for unauth | Apr 4, 2025 | 9.8 | 28 | NO | NO |
CVE-2017-18634CRITICAL The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php. | Sep 16, 2019 | 9.8 | 28 | NO | NO |
CVE-2023-1597HIGH The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing una | Jul 10, 2023 | 8.8 | 26 | NO | NO |
CVE-2025-50005MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows DOM-Based XSS.This issue affects tag | Jan 22, 2026 | 6.5 | 25 | NO | NO |
CVE-2025-62031HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer.This issue affects tagDiv Composer: from n/ | Nov 6, 2025 | 7.1 | 24 | NO | NO |
CVE-2024-3813HIGH The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8 via the 'td_block_title' shortcode 'block_template_id' attr | Jun 15, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tagdiv.
Media articles that mention a CVE ID that affects a product developed by Tagdiv — matched by CVE ID, not by vendor name.