The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-12-12T17:54:51.323Z

Updated:

Reserved: 2022-11-10T16:15:50.748Z


Link: CVE-2022-3930

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2022-12-12T18:15:12.103

Modified: 2023-11-07T03:51:58.713


Link: CVE-2022-3930

JSON object: View

cve-icon Redhat Information

No data.

CWE

No CWE.