PoC Index

CVE-2022-3930

MEDIUM 6.5EPSS 0.6%

The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.61% chance of exploitation in the next 30 days, 47th percentile
Published
2022-12-12
Updated
2025-04-22

Proof-of-concept exploits (1)

References

Related