CVE-2022-3930
PoC —CVSS 3.1
6.5 medium
EPSS
<1%p47
Published
()
Modified
Description
The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.
- Vendors
- wpwax
- Products
- directorist
- Ecosystems
- WordPress
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.