CVE-2022-2046

Source
https://cve.org/CVERecord?id=CVE-2022-2046
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-2046.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-2046
Published
2022-08-08T13:46:03Z
Modified
2026-07-15T01:48:52.113030828Z
Summary
Directorist - Business Directory Plugin < 7.2.3 - Admin+ Arbitrary File Upload
Details

The Directorist WordPress plugin before 7.2.3 allows administrators to download other plugins from the same vendor directly to the site, but does not check the URL domain it gets the zip files from. This could allow administrators to run code on the server, which is a problem in multisite configurations.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "7.2.3"
                },
                {
                    "last_affected": "7.2.3"
                }
            ]
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "fixed": "7.2.3"
                }
            ]
        }
    ],
    "cna_assigner": "WPScan",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/2xxx/CVE-2022-2046.json",
    "cwe_ids": [
        "CWE-434"
    ]
}
References

Affected packages

Git / github.com/sovware/directorist

Affected ranges

Type
GIT
Repo
https://github.com/sovware/directorist
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:wpwax:directorist:*:*:*:*:*:wordpress:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "7.2.3"
        }
    ]
}

Affected versions

released-v7.*
released-v7.0.4
v7.*
v7.0
v7.0.3.2
v7.0.3.3
v7.0.4.1
v7.0.5
v7.0.5.1
v7.0.5.2
v7.0.5.3
v7.0.5.4
v7.0.5.6
v7.0.6
v7.0.6.1
v7.0.6.2
v7.0.6.3
v7.0.7
v7.0.8
v7.1.0
v7.1.1
v7.1.2
v7.2.0
v7.2.1
v7.2.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-2046.json"