The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Directorist | Wpwax | * | 7.4.2.2 (excluding) |
References