VulnerabilityModified
CVE-2022-3930
The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.
MEDIUM 6.5EPSS 0.61%
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Affected
- wpwax/directorist
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/8728d02a-51db-4447-a843-0264b6ceb413Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/8728d02a-51db-4447-a843-0264b6ceb413Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.