PoC Index

CVE-2022-3477

CRITICAL 9.8EPSS 3.6%

The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
3.58% chance of exploitation in the next 30 days, 89th percentile
Nuclei
critical · CWE-287
Published
2022-11-14
Updated
2025-04-30

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related