PHP Object Instantiation Vulnerability in tagDiv Composer Plugin for WordPress
CVE-2024-13645
9.8CRITICAL
What is CVE-2024-13645?
The tagDiv Composer plugin for WordPress is susceptible to a PHP Object Instantiation vulnerability in all versions up to 5.3 through its module parameter. This flaw permits unauthenticated attackers to instantiate a PHP object, raising security concerns primarily when additional plugins or themes that include a PHP Object Injection (POP) chain are present. Without these components, the vulnerability is largely inert, but if a POP chain is available, it could empower attackers to perform malicious actions, including deleting files, accessing sensitive information, or executing arbitrary code, contingent on the specific POP chain's configuration.
Affected Version(s)
tagDiv Composer * <= 5.3