PT-2022-22320 · Tagdiv · Newspaper+2

Truoc Phan

·

Published

2022-11-14

·

Updated

2026-04-14

·

CVE-2022-3477

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions tagDiv Composer WordPress plugin versions prior to 3.5 Newspaper WordPress theme versions prior to 12.1 Newsmag WordPress theme versions prior to 5.2.2
Description The issue concerns the improper implementation of the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address.
Recommendations For tagDiv Composer WordPress plugin versions prior to 3.5, update to version 3.5 or later. For Newspaper WordPress theme versions prior to 12.1, update to version 12.1 or later. For Newsmag WordPress theme versions prior to 5.2.2, update to version 5.2.2 or later.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-3477

Affected Products

Newsmag
Newspaper
Tagdiv Composer