The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-11-14T00:00:00

Updated: 2022-11-14T00:00:00

Reserved: 2022-10-12T00:00:00


Link: CVE-2022-3477

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-11-14T15:15:49.257

Modified: 2022-11-16T19:04:16.773


Link: CVE-2022-3477

JSON object: View

cve-icon Redhat Information

No data.

CWE