CVE-2022-3930

Advisory lineage Upstream: 0 Downstream: 1
Modified
Published: 12 Dec 2022, 17:54
Last modified:22 Apr 2025, 17:50

Vulnerability Summary

Overall Risk (default)
medium
45/100
CVSS Score
8.8 HIGH
v3.1 (wordfence)
EPSS Score
0.32% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

12 Dec 2022, 17:54
Published
Vulnerability first disclosed
22 Apr 2025, 17:50
Last Modified
Vulnerability information updated

Description

The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
  • v3.1HIGHScore: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.32% Percentile: 55%

Techniques & Countermeasures

  • CWE-639Authorization Bypass Through User-Controlled Key

    The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Affected Systems

  • unknowndirectorist

    < 7.4.2.2

  • wordpressdirectorist

    ≤ 7.4.2.1

  • wpwaxdirectorist

    < 7.4.2.2

References (2)