WordPress Directorist plugin <= 7.5.4 - Arbitrary Content Deletion vulnerability
CVE-2023-35052
4.3MEDIUM
Summary
The WP Business Directory Plugin by wpWax has a missing authorization vulnerability that can be exploited to bypass incorrectly configured access control mechanisms. This issue affects users of the Directorist plugin, allowing unauthorized access and actions that may compromise the integrity and confidentiality of user data. The vulnerable versions span from an unspecified release up to 7.5.4, making it crucial for services utilizing this plugin to review their security configurations and implement necessary updates to safeguard against potential exploitation.
Affected Version(s)
Directorist <= 7.5.4
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafshanzani Suhada (Patchstack Alliance)