CVE-2022-3477
tagDiv Composer < 3.5 - Unauthenticated Account Takeover
Record summary
CVE-2022-3477 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 24, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2025 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
NewsmagBrowse tagDiv / Newsmag | CVE List | 5.2.2 to < 5.2.2 | affected |
NewspaperBrowse tagDiv / Newspaper | CVE List | 12.1 to < 12.1 | affected |
tagDiv ComposerBrowse tagDiv / tagDiv Composer | CVE List | 3.5 to < 3.5 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALWordPress tagDiv Composer < 3.5 - Authentication BypassCVSS 9.8
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address
Impact
Unauthenticated attackers who know a user's email address can bypass authentication through the Facebook login feature to gain complete access to any user account including administrator accounts on WordPress sites using tagDiv Composer.
Remediation
Fixed in 3.5
Source: ProjectDiscovery