Record summary

CVE-2022-2376 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

Directorist – WordPress Business Directory Plugin with Classified Ads Listings

CVE List7.3.1 to < 7.3.1affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Directorist <7.3.1 - Information DisclosureCVSS 5.3

WordPress Directorist plugin before 7.3.1 is susceptible to information disclosure. The plugin discloses the email address of all users in an AJAX action available to both unauthenticated and authenticated users.

Impact

An attacker can gain sensitive information about the WordPress installation, potentially leading to further attacks.

Remediation

Fixed in version 7.3.1.

WeaknessesCWE-862
AuthorsRandom-Robbie
Template tagscvecve2022wp-pluginwpscanwordpresswpdirectoristunauthdisclosurewpwaxvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:wpwax:directorist:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2