Lucene search

K
wpexploitKrzysztof ZającWPEX-ID:437C4330-376A-4392-86C6-C4C7ED9583AD
HistoryAug 10, 2022 - 12:00 a.m.

Directorist < 7.3.1 - Unauthenticated Email Address Disclosure

2022-08-1000:00:00
Krzysztof Zając
133
directorist
email disclosure
unauthenticated access

EPSS

0.037

Percentile

91.8%

The plugin discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users

https://example.com/wp-admin/admin-ajax.php?action=directorist_author_pagination

EPSS

0.037

Percentile

91.8%

Related for WPEX-ID:437C4330-376A-4392-86C6-C4C7ED9583AD