CVE-2022-2377: Directorist < 7.3.0 - Subscriber+ Arbitrary E-mail Sending
Published Aug 22, 2022
·Updated
The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing any authenticated users to send arbitrary emails on behalf of the blog
Affected Software
1 affected component
wpWax Directorist Wordpress<7.3.0
Event History
Aug 22, 2022
CVE Published
via MITRE·03:02 PM
Data Sourced
via MITRE·03:02 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Directorist plugin vulnerability?
The vulnerability ID for this Directorist plugin vulnerability is CVE-2022-2377.
2
What is the severity of CVE-2022-2377?
The severity of CVE-2022-2377 is medium with a CVSS score of 4.3.
3
How does CVE-2022-2377 allow arbitrary email sending?
CVE-2022-2377 allows any authenticated users to send arbitrary emails on behalf of the blog due to the lack of authorization and CSRF checks in an AJAX action.
4
How can I fix CVE-2022-2377 in the Directorist plugin?
To fix CVE-2022-2377, please update the Directorist plugin to version 7.3.0 or later.
5
Where can I find more information about CVE-2022-2377?
You can find more information about CVE-2022-2377 at the following reference link: [link](https://wpscan.com/vulnerability/f4e606e9-0664-42fb-a59b-21de306eb530).