PHP Object Instantiation Vulnerability in tagDiv Composer Plugin for WordPress
CVE-2024-13645

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
4 April 2025

What is CVE-2024-13645?

The tagDiv Composer plugin for WordPress is susceptible to a PHP Object Instantiation vulnerability in all versions up to 5.3 through its module parameter. This flaw permits unauthenticated attackers to instantiate a PHP object, raising security concerns primarily when additional plugins or themes that include a PHP Object Injection (POP) chain are present. Without these components, the vulnerability is largely inert, but if a POP chain is available, it could empower attackers to perform malicious actions, including deleting files, accessing sensitive information, or executing arbitrary code, contingent on the specific POP chain's configuration.

Affected Version(s)

tagDiv Composer * <= 5.3

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Mazzolini
.