CVE Database /
CVE-2022-2377
CVE · Medium
CVE-2022-2377 — Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.3.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-2377
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.3.0 |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 7.3.0
|
7.3.0 |
2022-07-26 |
—
|
CVE-2022-2377
The Directorist plugin for WordPress versions 7.2.3 and earlier contains an authorization bypass vulnerability in the send_announcement() function that lacks proper capability verification. This flaw allows users with subscriber-level access to send emails on behalf of the WordPress site without proper authorization checks. The vulnerability only affects authenticated users but does not require elevated privileges to exploit.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings