CVE-2022-3930: medium-severity vulnerability in Directorist
Directorist < 7.4.2.2 - Subscriber+ Arbitrary User Password Update via IDOR
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 0.6%
exploitation probability
0.6%top 52% of all CVEs
observed exploitation
nono source reports it
The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Affected products
Unknown · DirectoristRelated CVEs — Directorist
In the same product, most dangerous first.