Security Advisory

CVE-2022-3477

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-11-14 00:00:00
Last updated 2025-04-30 19:15:06
Assigner WPScan
State PUBLISHED

Description

The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address