S4E just found a medium-severity finding from asset blacklist checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-2376 Scanner

CVE-2022-2376 scanner - Information Disclosure vulnerability in Directorist

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
5.3
CVSS
Description

The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Directorist – WordPress Business Directory Plugin with Classified Ads Listings
AFFECTED< 7.3.1SAFE ✓≥ 7.3.1
Updated Sep 18, 2026View on NVD →
Detail

Directorist is a popular WordPress plugin that is designed to help users create online directories. It is a user-friendly tool that has been utilized by businesses, organizations, and individuals to create directories of various types. Directorist is commonly used for creating business directories, employee directories, restaurant directories, and many more. It simplifies the task of creating and managing online directories by providing a range of customization options.

Recently, a vulnerability was discovered in the Directorist WordPress plugin. This vulnerability is known as CVE-2022-2376. It was found that the plugin was exposing the email addresses of all users, whether authenticated or not, in an AJAX action that was easily available to everyone. This flaw could be exploited by hackers to get access to sensitive information and launch targeted attacks against vulnerable websites.

Upon exploiting this vulnerability, attackers can gain access to email addresses of all users including their names and other personal information. This can compromise the privacy of users and lead to phishing attacks, identity theft, and spamming. Since email addresses can also be used as login credentials for other accounts, hackers could use them to launch attacks against those accounts as well. 

In conclusion, the CVE-2022-2376 vulnerability detected in the Directorist WordPress plugin exposes users' email addresses to all visitors through an AJAX action. This could lead to various cyber attacks targeting vulnerable websites. However, taking the necessary precautions could help protect against such attacks. It is important to keep the Directorist plugin updated and regularly review user permissions. Readers can use the pro features of the s4e.io platform to easily and quickly learn about vulnerabilities in their digital assets, making sure that they stay ahead of potential threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, following precautions can be taken:

  • Update the Directorist plugin to the latest version (7.3.1 or later).
  • Review user permissions and make sure that only those users who need access to email addresses of other users have it.
  • Restrict access to AJAX actions to authenticated users only.
  • Set up a website firewall to monitor and filter requests to vulnerable endpoints.
  • Implement two-factor authentication to strengthen login credentials.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.