CVE · High

CVE-2024-3813 — tagDiv Composer [td-composer] < 4.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3813 tagDiv Composer [td-composer] < 4.9 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 8.8 < 4.9 4.9 2024-04-18

CVE-2024-3813

The tagDiv Composer plugin for WordPress contains a local file inclusion vulnerability in versions 4.8 and below through the 'block_template_id' parameter of the 'td_block_title' shortcode. Authenticated users with at least contributor-level access can exploit this flaw to load and execute arbitrary files from the server, potentially running malicious PHP code. This vulnerability could allow attackers to circumvent security restrictions, access confidential information, or execute code if PHP files have been uploaded to the system.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.