CVE-2022-2377
22.08.2022, 15:15
The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing any authenticated users to send arbitrary emails on behalf of the blog
| Vendor | Product | Version |
|---|---|---|
| wpwax | directorist | 𝑥 < 7.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration