CVE-2022-2046: Directorist - Business Directory Plugin < 7.2.3 - Admin+ Arbitrary File Upload
The Directorist WordPress plugin before 7.2.3 allows administrators to download other plugins from the same vendor directly to the site, but does not check the URL domain it gets the zip files from. This could allow administrators to run code on the server, which is a problem in multisite configurations.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Directorist WordPress plugin vulnerability?
The vulnerability ID for the Directorist WordPress plugin vulnerability is CVE-2022-2046.
What is the severity of CVE-2022-2046?
CVE-2022-2046 has a severity rating of medium.
How does CVE-2022-2046 affect the Directorist WordPress plugin?
CVE-2022-2046 allows administrators to download other plugins from the same vendor directly to the site, but does not check the URL domain it gets the zip files from.
What is the affected software for CVE-2022-2046?
The affected software for CVE-2022-2046 is the Directorist WordPress plugin before version 7.2.3.
How can I fix the vulnerability CVE-2022-2046 in the Directorist WordPress plugin?
To fix the vulnerability CVE-2022-2046 in the Directorist WordPress plugin, you should update to version 7.2.3 or later.