The tagDiv Composer WordPress plugin before 4.2, used as...
        
  Moderate severity
        
          Unreviewed
      
        Published
          Sep 11, 2023 
          to the GitHub Advisory Database
          •
          Updated Apr 4, 2024 
      
  
Description
        Published by the National Vulnerability Database
      Sep 11, 2023 
    
  
        Published to the GitHub Advisory Database
      Sep 11, 2023 
    
  
        Last updated
      Apr 4, 2024 
    
  
The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in a REST route and does not validate as well as escape some parameters when outputting them back, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.
References