9.8
CVSSv3

CVE-2022-3477

Published: 14/11/2022 Updated: 16/11/2022
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The tagDiv Composer WordPress plugin prior to 3.5, required by the Newspaper WordPress theme prior to 12.1 and Newsmag WordPress theme prior to 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated malicious users to login as any user by just knowing their email address

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tagdiv composer project tagdiv composer

newsmag project newsmag

newspaper project newspaper