CVE-2024-3813
The tagDiv Composer plugin for WordPress contains a local file inclusion vulnerability in versions 4.8 and below through the 'block_template_id' parameter of the 'td_block_title' shortcode. Authenticated users with at least contributor-level access can exploit this flaw to load and execute arbitrary files from the server, potentially running malicious PHP code. This vulnerability could allow attackers to circumvent security restrictions, access confidential information, or execute code if PHP files have been uploaded to the system.
Based on public CVE data (MITRE/NVD).