aDirectory <= 3.0.3 - Missing Authorization
medium
The aDirectory – WP Business Directory Plugin and Classified Ads Listings Directory plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.0.3. This makes it possible for authenticated attackers, with Subscriber-level access and...
- CVSS:
- 4.3
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.4
- Disclosed:
- Jan 27, 2026
CVE-2025-67975 on NVD →
aDirectory – WP Business Directory Plugin and Classified Ads Listings Directory [adirectory] < 2.3.5
unknown
[en] The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the adqs_delete_listing() function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and...
- Affected:
- up to 2.3.5
- Fixed in:
- 2.3.5
- Disclosed:
- Feb 12, 2025
CVE-2024-13541 on NVD →
aDirectory – WordPress Directory Listing Plugin <= 2.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion
medium
The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the adqs_delete_listing() function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and abov...
- CVSS:
- 4.3
- Affected:
- up to 2.3
- Fixed in:
- 2.3.5
- Disclosed:
- Feb 11, 2025
CVE-2024-13541 on NVD →
aDirectory – WP Business Directory Plugin and Classified Ads Listings Directory [adirectory] < 1.9
unknown
<p>WordPress aDirectory Plugin <= 1.6.5 is vulnerable to PHP Object Injection</p><p>Software: aDirectory</p><p>Fixed in version 1.9 </p><p>Affected Version <= 1.6.5</p>
- Affected:
- up to 1.9
- Fixed in:
- 1.9
- Disclosed:
- Jan 21, 2025
aDirectory – WordPress Directory Listing Plugin <= 1.6.5 - Unauthenticated PHP Object Injection
high
The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.5 via deserialization of untrusted input from the 'carousel_settings' attribute in the 'adqs_taxonomies' shortcode. This makes it possible for unauthenticated attacker...
- CVSS:
- 7.5
- Affected:
- up to 1.6.5
- Fixed in:
- 1.9
- Disclosed:
- Jan 20, 2025
aDirectory <= 1.3 - Unauthenticated Arbitrary File Upload
critical
The aDirectory – Directory Listing WordPress Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remo...
- CVSS:
- 9.8
- Affected:
- up to 1.3
- Fixed in:
- 1.3.1
- Disclosed:
- Oct 24, 2024
CVE-2024-50420 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database