Critical severity9.8NVD Advisory· Published Nov 14, 2022· Updated Jun 17, 2026
CVE-2022-3477
CVE-2022-3477
Description
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- cpe:2.3:a:newspaper_project:newspaper:*:*:*:*:*:wordpress:*:*Range: <12.1
- cpe:2.3:a:tagdiv_composer_project:tagdiv_composer:*:*:*:*:*:wordpress:*:*Range: <3.5
- tagDiv/Newsmagv5Range: 5.2.2
- Range: 3.5
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/993a95d2-6fce-48de-ae17-06ce2db829efnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.