Showing 1 vulnerability on this page for newsmag

Signals CISA KEV Ransomware Nuclei
newsmag_project vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

tagDiv Composer < 3.5 - Unauthenticated Account Takeover

The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address

CWE-287Nov 14, 20221 related artifact
CVSS9.8v3.1EPSS3.55%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX