← WordPress Vulnerabilities
WordPress security by component

Cool Tag Cloud

Cool Tag Cloud is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Feb 20, 2026; the highest CVE/CNA score is 8.1.

Plugin slug: cool-tag-cloud

CVE-2025-69011: Cool Tag Cloud: Cross-site scripting

Cool Tag Cloud is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedFeb 20, 2026
Safe version guidanceSee mitigation notes
Safe version
Feb 20, 2026 CVE-2025-69011
Cool Tag Cloud: Cross-site scripting
Cool Tag Cloud is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Dec 05, 2025 CVE-2025-13614
Cool Tag Cloud: Cross-site scripting
Cool Tag Cloud is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE8.1
NVDPending
Nov 01, 2021 CVE-2021-24682
Cool Tag Cloud: Cross-site scripting
Cool Tag Cloud is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4