CVE-2022-3477
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.61% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- newsmag project/newsmag · newspaper project/newspaper · tagdiv composer project/tagdiv composer
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/993a95d2-6fce-48de-ae17-06ce2db829efExploit, Third Party Advisory
- https://wpscan.com/vulnerability/993a95d2-6fce-48de-ae17-06ce2db829efExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.