The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessing sensitive system information.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/6aad6454-de1b-4304-9c14-05e28d08b253 | exploit vdb entry third party advisory technical description |