CVE-2022-3930: Directorist < 7.4.2.2 - Subscriber+ Arbitrary User Password Update via IDOR
Published Dec 12, 2022
·Updated
The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.
Affected Software
1 affected component
wpWax Directorist Wordpress<7.4.2.2
Event History
Dec 12, 2022
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of the Directorist WordPress plugin vulnerability?
The vulnerability ID is CVE-2022-3930.
2
What is the severity of CVE-2022-3930?
The severity of CVE-2022-3930 is medium with a score of 6.5.
3
How does the IDOR vulnerability in the Directorist WordPress plugin work?
The IDOR vulnerability allows an attacker to change the password of arbitrary users instead of their own.
4
Which version of the Directorist WordPress plugin is affected by CVE-2022-3930?
The Directorist WordPress plugin version 7.4.2.2 and below are affected by CVE-2022-3930.
5
How can I fix the IDOR vulnerability in the Directorist WordPress plugin?
To fix the IDOR vulnerability, update your Directorist WordPress plugin to version 7.4.2.2 or higher.