CVE-2022-2376

Source
https://cve.org/CVERecord?id=CVE-2022-2376
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-2376.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-2376
Published
2022-09-05T12:35:19Z
Modified
2026-07-15T01:48:56.825289179Z
Summary
Directorist < 7.3.1 - Unauthenticated Email Address Disclosure
Details

The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users

Database specific
{
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/2xxx/CVE-2022-2376.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "7.3.1"
                },
                {
                    "last_affected": "7.3.1"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "fixed": "7.3.1"
                }
            ],
            "source": "DESCRIPTION"
        }
    ],
    "cna_assigner": "WPScan"
}
References

Affected packages

Git / github.com/sovware/directorist

Affected ranges

Type
GIT
Repo
https://github.com/sovware/directorist
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:wpwax:directorist:*:*:*:*:*:wordpress:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "7.3.1"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

released-v7.*
released-v7.0.4
v7.*
v7.0
v7.0.3.2
v7.0.3.3
v7.0.4.1
v7.0.5
v7.0.5.1
v7.0.5.2
v7.0.5.3
v7.0.5.4
v7.0.5.6
v7.0.6
v7.0.6.1
v7.0.6.2
v7.0.6.3
v7.0.7
v7.0.8
v7.1.0
v7.1.1
v7.1.2
v7.2.0
v7.2.1
v7.2.2
v7.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-2376.json"