CVE-2022-3930 PUBLISHED CVSS 6.5 MEDIUM

The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.

EPSS 0.32% · 54.8th percentile

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.32%
54.8th percentile

Affected Products

VendorProductVersions
UnknownDirectorist0
wpwaxdirectorist0

Timeline

References

Open in Interactive Console →