The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing any authenticated users to send arbitrary emails on behalf of the blog
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-08-22T15:02:09

Updated: 2022-08-22T15:02:09

Reserved: 2022-07-11T00:00:00


Link: CVE-2022-2377

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-08-22T15:15:14.733

Modified: 2023-06-30T21:35:58.937


Link: CVE-2022-2377

JSON object: View

cve-icon Redhat Information

No data.