CVE-2024-1322: Directorist <= 7.8.4 - Missing Authorization to Unauthenticated Settings Change
The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'setupwizard' function in all versions up to, and including, 7.8.4. This makes it possible for unauthenticated attackers to recreate default pages and enable or disable monetization and change map provider.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1322?
CVE-2024-1322 is considered a high severity vulnerability due to the risk of unauthorized data modification.
How do I fix CVE-2024-1322?
To fix CVE-2024-1322, update the Directorist WordPress Business Directory Plugin with Classified Ads Listings to version 7.8.5 or later.
What causes CVE-2024-1322?
CVE-2024-1322 is caused by a missing capability check on the 'setup_wizard' function in the affected plugin.
Which versions of the Directorist plugin are affected by CVE-2024-1322?
All versions of the Directorist WordPress Business Directory Plugin with Classified Ads Listings up to and including 7.8.4 are affected by CVE-2024-1322.
Who is affected by CVE-2024-1322?
Any site using the Directorist WordPress Business Directory Plugin with Classified Ads Listings version 7.8.4 or prior is potentially affected by CVE-2024-1322.