CVE Feed

    Dashboard / CVE / CVE-2022-3477

    CVE-2022-3477

    The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address

    Published:Nov 14, 2022
    Last Modified:Apr 30, 2025
    EPS:Nov 14, 2022
    EPSS Score:0.0107
    CVSS Score:9.8

    Affected Products

    Vendor
    Newsmag Project
    Product
    Newsmag
    Vendor
    Newspaper Project
    Product
    Newspaper
    Vendor
    Tagdiv Composer Project
    Product
    Tagdiv Composer

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High