CVE-2022-3961: Directorist < 7.4.4 - Subscriber+ Sensitive Information Disclosure
Published Dec 19, 2022
·Updated
The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessing sensitive system information.
Affected Software
1 affected component
wpWax Directorist Wordpress<7.4.4
Event History
Dec 19, 2022
CVE Published
via MITRE·01:41 PM
Data Sourced
via MITRE·01:41 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Directorist WordPress plugin vulnerability?
The vulnerability ID for this Directorist WordPress plugin vulnerability is CVE-2022-3961.
2
What is the severity of CVE-2022-3961?
CVE-2022-3961 has a severity rating of 6.5, which is considered medium.
3
What is the affected software version of this vulnerability?
The affected software version of this vulnerability is Directorist WordPress plugin version up to exclusive 7.4.4.
4
What can an attacker do with this vulnerability?
An attacker can access sensitive system information even with low privileges (like subscribers) using this vulnerability.
5
Is there a fix available for CVE-2022-3961?
Yes, the fix for CVE-2022-3961 is to update the Directorist WordPress plugin to version 7.4.4 or later.