CVE-2022-2046 - CVE House
Back to Database
Status published Medium CVE-2022-2046

Directorist - Business Directory Plugin < 7.2.3 - Admin+ Arbitrary File Upload

Vulnerability Description

The Directorist WordPress plugin before 7.2.3 allows administrators to download other plugins from the same vendor directly to the site, but does not check the URL domain it gets the zip files from. This could allow administrators to run code on the server, which is a problem in multisite configurations.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-2046

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Rafie Muhammad

Affected Vendor

Affected Software

Directorist – WordPress Business Directory Plugin with Classified Ads Listings
Vulnerable Versions:
7.2.3

Timeline

Official Publish: August 8th, 2022
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Weaknesses (CWE)