The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.
History

Tue, 22 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2022-12-12T17:54:51.323Z

Updated: 2025-04-22T17:50:22.802Z

Reserved: 2022-11-10T16:15:50.748Z

Link: CVE-2022-3930

cve-icon Vulnrichment

Updated: 2024-08-03T01:27:53.132Z

cve-icon NVD

Status : Modified

Published: 2022-12-12T18:15:12.103

Modified: 2025-04-22T18:15:57.287

Link: CVE-2022-3930

cve-icon Redhat

No data.