PT-2025-14844 · WordPress · Tagdiv Composer
Michael Mazzolini
·
Published
2025-04-04
·
Updated
2025-04-09
·
CVE-2024-13645
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
tagDiv Composer plugin for WordPress versions up to, and including, 5.3
Description
The issue allows unauthenticated attackers to instantiate a PHP object via the
module parameter. This vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present, it may allow the attacker to perform actions like deleting arbitrary files, retrieving sensitive data, or executing code, depending on the POP chain present.Recommendations
For versions up to, and including, 5.3, consider disabling the module parameter to minimize the risk of exploitation until a patch is available. Restrict access to sensitive data and files to prevent potential damage in case a POP chain is present via another plugin or theme.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tagdiv Composer