CVE-2022-3477
Last modified
CVE-2022-3477 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address. EPSS estimates a 3.55% chance of exploitation in the next 30 days.
Description
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Newsmag Project | Newsmag | < 5.2.2 |
| Newspaper Project | Newspaper | < 12.1 |
| Tagdiv Composer Project | Tagdiv Composer | < 3.5 |
References
- https://wpscan.com/vulnerability/993a95d2-6fce-48de-ae17-06ce2db829efExploit, Third Party Advisory
- https://wpscan.com/vulnerability/993a95d2-6fce-48de-ae17-06ce2db829efExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3477?
How severe is CVE-2022-3477?
How do I fix CVE-2022-3477?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-34763A CWE-345: Insufficient Verification of Data Authenticity vu…7.5
- CVE-2022-34764A CWE-119: Improper Restriction of Operations within the Bou…7.5
- CVE-2022-34765A CWE-73: External Control of File Name or Path vulnerabilit…5.3
- CVE-2022-34767Web page which "wizardpwd.asp" ALLNET Router model WR0500AC …9.8
- CVE-2022-34768insert HTML / js code inside input how to get to the vulnera…7.5
- CVE-2022-34769Michlol - rashim web interface Insecure direct object refere…5.5
- CVE-2022-34770Tabit - sensitive information disclosure. Several APIs on th…7.5
- CVE-2022-34771Tabit - arbitrary SMS send on Tabits behalf. The resend OTP …3.5
- CVE-2022-34772Tabit - password enumeration. Description: Tabit - password …8.8
- CVE-2022-34773Tabit - HTTP Method manipulation. https://bridge.tabit.cloud…9.8
- CVE-2022-34774Tabit - Arbitrary account modification. One of the endpoints…5.3
- CVE-2022-34775Tabit - Excessive data exposure. Another endpoint mapped by …7.5
Are you affected by CVE-2022-3477?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
