CVE-2022-2376: vulnerability in Directorist – WordPress Business Directory…
Directorist < 7.3.1 - Unauthenticated Email Address Disclosure
Published · Updated
40Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 1.8%
from disclosure to weapon
Published on NVDSep 5
VulnCheck+504d
exploitation probability
1.8%top 22% of all CVEs
observed exploitation
yesVulnCheck
The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users
Affected products
Unknown · Directorist – WordPress Business Directory Plugin with Classified Ads ListingsRelated CVEs — Directorist – WordPress Business Directory…
In the same product, most dangerous first.