CVE-2022-3477 is a critical authentication bypass vulnerability affecting the tagDiv Composer WordPress plugin (versions prior to 3.5), which is required by the Newspaper (prior to 12.1) and Newsmag (prior to 5.2.2) WordPress themes. This flaw allows unauthenticated attackers to log in as any user by simply knowing their email address, due to improper implementation of the Facebook login feature. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with low complexity, leading to complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, public Nuclei templates exist for this vulnerability, and it has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.2.2CPE matchmatch criteria | cpe:2.3:a:newsmag_project:newsmag:*:*:*:*:*:wordpress:*:* | ||
< 12.1CPE matchmatch criteria | cpe:2.3:a:newspaper_project:newspaper:*:*:*:*:*:wordpress:*:* | ||
< 3.5CPE matchmatch criteria | cpe:2.3:a:tagdiv_composer_project:tagdiv_composer:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.