CVE-2022-3930

Source
https://cve.org/CVERecord?id=CVE-2022-3930
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-3930.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-3930
Downstream
Related
Published
2022-12-12T17:54:51.323Z
Modified
2026-08-12T03:51:34.466542263Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Directorist < 7.4.2.2 - Subscriber+ Arbitrary User Password Update via IDOR
Details

The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "7.4.2.2"
                }
            ]
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "fixed": "7.4.2.2"
                }
            ]
        }
    ],
    "cna_assigner": "WPScan",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/3xxx/CVE-2022-3930.json"
}
References

Affected packages

Git / github.com/sovware/directorist

Affected ranges

Type
GIT
Repo
https://github.com/sovware/directorist
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:wpwax:directorist:*:*:*:*:*:wordpress:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "7.4.2.2"
        }
    ]
}

Affected versions

released-v7.*
released-v7.0.4
v7.*
v7.0
v7.0.3.2
v7.0.3.3
v7.0.4.1
v7.0.5
v7.0.5.1
v7.0.5.2
v7.0.5.3
v7.0.5.4
v7.0.5.6
v7.0.6
v7.0.6.1
v7.0.6.2
v7.0.6.3
v7.0.7
v7.0.8
v7.1.0
v7.1.1
v7.1.2
v7.2.0
v7.2.1
v7.2.2
v7.3.0
v7.3.1
v7.3.1.2
v7.3.2
v7.3.3
v7.4.0
v7.4.1
v7.4.2
v7.4.2.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-3930.json"