CVE-2022-3477
The WordPress tagDiv Composer plugin before version 3.5 contains a broken authentication flaw that allows attackers to execute administrative actions without proper authorization, potentially leading to unauthorized admin account creation or compromise. A researcher named Truoc Phan from Techlab Corporation identified this issue, which enables threat actors to bypass privilege restrictions and perform operations restricted to higher-level users. The vulnerability was resolved starting with version 3.5 of the plugin.
Based on public CVE data (MITRE/NVD).