WP Clinic
Log in Sign up

CVE · Medium

CVE-2022-3930 — Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.4.2.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3930 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.4.2.2 Authorization Bypass Through User-Controlled Key Medium 6.5 < 7.4.2.2 7.4.2.2 2022-11-21

CVE-2022-3930

The Directorist plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 7.4.2.1. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for subscriber-level attackers to change user passwords and potentially take over administrator accounts.

Source: Wordfence

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.