CVE · Critical

CVE-2022-3477 — tagDiv Composer [td-composer] < 3.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3477 tagDiv Composer [td-composer] < 3.5 Improper Authentication Critical 9.8 < 3.5 3.5 2022-10-24

CVE-2022-3477

The WordPress tagDiv Composer plugin before version 3.5 contains a broken authentication flaw that allows attackers to execute administrative actions without proper authorization, potentially leading to unauthorized admin account creation or compromise. A researcher named Truoc Phan from Techlab Corporation identified this issue, which enables threat actors to bypass privilege restrictions and perform operations restricted to higher-level users. The vulnerability was resolved starting with version 3.5 of the plugin.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.