The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2022-12-12T17:54:51.323Z

Updated: 2024-08-03T01:27:53.132Z

Reserved: 2022-11-10T16:15:50.748Z

Link: CVE-2022-3930

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-12-12T18:15:12.103

Modified: 2023-11-07T03:51:58.713

Link: CVE-2022-3930

cve-icon Redhat

No data.