5.3

CVE-2022-2376

Exploit

Directorist < 7.3.1 - Unauthenticated Email Address Disclosure

Directorist <= 7.3.0 - Sensitive Information Disclosure

The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users
Mögliche Gegenmaßnahme
Directorist: AI-Powered Business Directory, Listings & Classified Ads: Update to version 7.3.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WpwaxDirectorist SwPlatformwordpress Version < 7.3.1
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Directorist: AI-Powered Business Directory, Listings & Classified Ads
Version *-7.3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.36% 0.68
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://wpscan.com/vulnerability/437c4330-376a-4392-86c6-c4c7ed9583ad
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/b20fa367-a12f-402a-a74a-2bb5fe090036
Third Party Advisory