The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_raw_html shortcode in all versions up to and including 5.4.5. This is due to insufficient input sanitization and output escaping in the vc_raw_html::render() method, which base64-decodes shortcode content (after a strip_tags() that is bypassed because the encoded payload contains no tags on save) and concatenates the result directly into the page HTML. Because WordPress's save-time wp_kses_post() filter only sees the inert base64 text inside a normal shortcode bracket and does not decode it, the dangerous tags survive into post_content and are emitted unescaped at render time. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page (for example, when an Editor or Administrator previews the pending post).
We have discovered 348 live websites that are affected by CVE-2026-12561.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 348 live websites (10% of tagDiv Composer install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 7 versions ( 15% of all versions) |
| 157 websites | |
| 39 websites | |
| 28 websites | |
| 14 websites | |
| 13 websites | |
| 9 websites | |
| 8 websites | |
| 6 websites | |
| 5 websites | |
| 5 websites |
| .com | 172 websites |
| .fr | 30 websites |
| .de | 16 websites |
| .net | 14 websites |
| .org | 11 websites |
| .it | 10 websites |
| .co.uk | 9 websites |
| .ru | 5 websites |
| .es | 5 websites |
| .com.br | 4 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.de | *,*** | ||
| ******.ru | *,*** | ||
| ***************.net | **,*** | ||
| *******.ie | **,*** | ||
| ********.org | **,*** | ||
| ***********.com | **,*** | ||
| **************************.com | ***,*** | ||
| ****.com | ***,*** | ||
| **********.com | ***,*** | ||
| *************.de | ***,*** |
FAQ