PT-2022-16256 · WordPress · Directorist

Krzysztof Zając

·

Published

2022-08-22

·

Updated

2023-06-30

·

CVE-2022-2377

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Directorist WordPress plugin versions prior to 7.3.0
Description The issue concerns a lack of authorization and CSRF checks in an AJAX action within the Directorist WordPress plugin. This allows any authenticated users to send arbitrary emails on behalf of the blog.
Recommendations For versions prior to 7.3.0, update to version 7.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX action until a patch is applied.

Exploit

Fix

Missing Authorization

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-2377

Affected Products

Directorist