cvedb.io
CVE-2022-3477
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2022-11-14T15:15:49.257 · Last modified 2026-06-17T04:59:36.020

Summary

The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address

Affected products

newsmag_project — newsmag

Does this affect you?

Add your gear to cvedb and we'll alert you only when newsmag_project ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.