Configurable Tag Cloud (CTC)

Configurable Tag Cloud (CTC) has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for Configurable Tag Cloud (CTC) has a vendor fix available, so running the current release closes it.

All of these findings were reported by Abdi Pranata. Configurable Tag Cloud (CTC) is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.1.12.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Configurable Tag Cloud (CTC) vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2023-28995

Configurable Tag Cloud <= 5.2 - Cross-Site Request Forgery via ctc_options_page()

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv5.3

Configurable Tag Cloud (CTC)

Keith S.

Author

Keith S.

3.7(10)
74/100
Last Updated
2023-03-29 (4y ago)
Active Installs
2,000+
Downloads
138,776
Requires WP
2.8+
Requires PHP
0+
Tested up to
WP 6.1.12
Created
2007-11-28 (19y ago)

The best new feature in WordPress 2.3 is the integration of tagging into the core of WordPress. However, the tag cloud widget & functions that are included leaves a lot to be desired. So, with time on my hands, I decided to whip up my own version of the tag cloud that lets you configure the tag cloud with all the customizations (well, almost, see below) the tag cloud template tag allows. You can find the plugin home page (and leave comments) here. NOTE Development on this plugin has STOPPED! I am looking for someone to take it over. Find more info here Upgrade I suggest using the built-in WordPress plugin update feature, but to manually upgrade, follow these instructions: 1. Deactivate the plugin in the WordPress admin menu. 2. Delete the existing tag-cloud.php file from the /wp-content/plugins folder. 3. Upload the tag_cloud folder to the /wp-content/plugins/ directory. 4. Activate Configurable Tag Cloud through the &#8216;Plugins’ menu in WordPress and add the widget to your sidebar. 5. (Optional) Add ctc() template tag to your theme. Can be configured either via the Options menu, or via parameters in the template tag.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C