Описание
The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.4.2.2 (исключая)
cpe:2.3:a:wpwax:directorist:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 55%
0.0032
Низкий
6.5 Medium
CVSS3
Дефекты
Связанные уязвимости
CVSS3: 6.5
github
около 3 лет назад
The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.
EPSS
Процентиль: 55%
0.0032
Низкий
6.5 Medium
CVSS3