CVE · Critical

CVE-2024-13645 — tagDiv Composer [td-composer] < 5.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13645 tagDiv Composer [td-composer] < 5.4 Improper Control of Generation of Code ('Code Injection') Critical 9.8 < 5.4 5.4 2025-04-03

CVE-2024-13645

The tagDiv Composer plugin for WordPress through version 5.3 contains a PHP object instantiation vulnerability accessible through the module parameter, allowing unauthenticated attackers to instantiate arbitrary PHP objects. While the plugin itself lacks a known property-oriented programming chain, the vulnerability becomes exploitable if another installed plugin or theme provides such a chain, potentially enabling attackers to delete files, exfiltrate sensitive information, or execute arbitrary code depending on what gadget chain is available.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.