CVE-2026-12561

tagDiv Composer <= 5.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_raw_html shortcode in all versions up to and including 5.4.5. This is due to insufficient input sanitization and output escaping in the vc_raw_html::render() method, which base64-decodes shortcode content (after a strip_tags() that is bypassed because the encoded payload contains no tags on save) and concatenates the result directly into the page HTML. Because WordPress's save-time wp_kses_post() filter only sees the inert base64 text inside a normal shortcode bracket and does not decode it, the dangerous tags survive into post_content and are emitted unescaped at render time. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page (for example, when an Editor or Administrator previews the pending post).


We have discovered 348 live websites that are affected by CVE-2026-12561.

Run a Free Instant Scan




Affected Software

Product  tagDiv Composer
Category Wordpress Plugins
Vulnerable Domains348 live websites (10% of tagDiv Composer install base)
Vulnerable Versions
  • from 0 through 5.4.5
Vulnerable Versions Count7 versions ( 15% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 25, 2026
  • Updated - Aug 25, 2026

Credits

  • Truoc Phan (finder)

Website Distribution by Country

Number of websites using CVE-2026-12561
United States157 websites



France39 websites
Germany28 websites
Cyprus14 websites
GB13 websites
Italy9 websites
India8 websites
Spain6 websites
Russia5 websites
Greece5 websites

Website Distribution by TLD

Number of websites using CVE-2026-12561
.com172 websites
.fr30 websites
.de16 websites
.net14 websites
.org11 websites
.it10 websites
.co.uk9 websites
.ru5 websites
.es5 websites
.com.br4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-12561

Top websites that are affected by CVE-2026-12561. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.de Germany*,***
******.ru Russia*,***
***************.net United States**,***
*******.ie United States**,***
********.org France**,***
***********.com United States**,***
**************************.com United States***,***
****.com United States***,***
**********.com United States***,***
*************.de Germany***,***
See full domain list

FAQ

CVE-2026-12561 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in tagDiv Composer
A total of 348 websites have been identified as vulnerable to CVE-2026-12561, based on global website indexing conducted by WebTechSurvey.
The tagDiv Composer is affected by the CVE-2026-12561 vulnerability.
tagDiv Composer versions up to and including 5.4.5 are vulnerable to CVE-2026-12561.