CVE-2024-13645
The tagDiv Composer plugin for WordPress through version 5.3 contains a PHP object instantiation vulnerability accessible through the module parameter, allowing unauthenticated attackers to instantiate arbitrary PHP objects. While the plugin itself lacks a known property-oriented programming chain, the vulnerability becomes exploitable if another installed plugin or theme provides such a chain, potentially enabling attackers to delete files, exfiltrate sensitive information, or execute arbitrary code depending on what gadget chain is available.
Based on public CVE data (MITRE/NVD).