PT-2022-24982 · WordPress · Directorist

Lana Codes

·

Published

2022-12-19

·

Updated

2022-12-22

·

CVE-2022-3961

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Directorist WordPress plugin versions prior to 7.4.4
Description The issue allows users with low privileges, such as subscribers, to access sensitive system information. This is due to the lack of proper access controls in the Directorist WordPress plugin.
Recommendations For versions prior to 7.4.4, update to version 7.4.4 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive system information until the update can be applied.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-3961

Affected Products

Directorist