4.9
CVSSv3

CVE-2022-2046

Published: 08/08/2022 Updated: 12/08/2022
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

The Directorist WordPress plugin prior to 7.2.3 allows administrators to download other plugins from the same vendor directly to the site, but does not check the URL domain it gets the zip files from. This could allow administrators to run code on the server, which is a problem in multisite configurations.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wpwax directorist