CVE-2022-2376
Description
The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users
CWE
- CWE-862 — CWE-862 Missing Authorization
Affected
- Unknown / Directorist – WordPress Business Directory Plugin with Classified Ads Listings — v=7.3.1 <7.3.1 [affected]
CVSS
- (none)
References
Source
cvelistV5-main/cves/2022/2xxx/CVE-2022-2376.json