CVE-2022-2376
Directorist < 7.3.1 - Unauthenticated Email Address Disclosure
Severity Score
5.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users
El plugin Directorist de WordPress versiones anteriores a 7.3.1, divulga la dirección de correo electrónico de todos los usuarios en una acción AJAX disponible tanto para usuarios no autenticados como para cualquier usuario autenticado
The plugin Directorist for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 7.3.0. This could allow unauthenticated attackers to extract sensitive user data such as emails.
*Credits:
Krzysztof Zając
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-07-11 CVE Reserved
- 2022-08-10 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/437c4330-376a-4392-86c6-c4c7ed9583ad | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wpwax Search vendor "Wpwax" | Directorist Search vendor "Wpwax" for product "Directorist" | < 7.3.1 Search vendor "Wpwax" for product "Directorist" and version " < 7.3.1" | wordpress |
Affected
|