CVE-2022-3930

The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:wpwax:directorist:*:*:*:*:*:wordpress:*:*

Information

Published : 2022-12-12 10:15

Updated : 2022-12-14 13:32


NVD link : CVE-2022-3930

Mitre link : CVE-2022-3930


JSON object : View

CWE
CWE-639

Authorization Bypass Through User-Controlled Key

Advertisement

dedicated server usa

Products Affected

wpwax

  • directorist