First published: Mon Nov 14 2022(Updated: )
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Newsmag | <5.2.2 | |
Newspaper Project Newspaper | <12.1 | |
Tagdiv Composer | <3.5 | |
<5.2.2 | ||
<12.1 | ||
<3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3477 has a severity rating that indicates it allows unauthenticated attackers to exploit the Facebook login feature.
To fix CVE-2022-3477, update the tagDiv Composer plugin to version 3.5 or later, and ensure the Newspaper theme is updated to version 12.1 or later, or the Newsmag theme to version 5.2.2 or later.
CVE-2022-3477 affects tagDiv Composer versions below 3.5, Newspaper theme versions below 12.1, and Newsmag theme versions below 5.2.2.
CVE-2022-3477 can be exploited by unauthenticated attackers who know the email addresses of users.
CVE-2022-3477 allows attackers to login as any user, which can lead to unauthorized access and potential data breaches.