cleantalk
Vulnerabilities and Security Researches

Directorist – WordPress Business Directory Plugin with Classified Ads Listings, CVE-2022-3930

CVE, Research URL

CVE-2022-3930

Published on
Dec 12, 2022
Research Description
The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.
Affected versions
max 7.4.2.2.
Status
vulnerable