CVE-2022-2376: Directorist < 7.3.1 - Unauthenticated Email Address Disclosure
Published Sep 5, 2022
·Updated
The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users
Affected Software
1 affected component
wpWax Directorist Wordpress<7.3.1
Event History
Sep 5, 2022
CVE Published
via MITRE·12:35 PM
Data Sourced
via MITRE·12:35 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-2376.
2
What is the severity of CVE-2022-2376?
The severity of CVE-2022-2376 is medium with a severity value of 5.3.
3
What does the Directorist WordPress plugin before version 7.3.1 disclose?
The Directorist WordPress plugin before version 7.3.1 discloses the email address of all users.
4
Who can access the AJAX action that exposes the email addresses?
Both unauthenticated and authenticated users can access the AJAX action that exposes the email addresses.
5
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at https://wpscan.com/vulnerability/437c4330-376a-4392-86c6-c4c7ed9583ad.