plugin

Adirectory Vulnerabilities

6 known security issues reported for the Adirectory WordPress plugin. Most recent disclosed Jan 27, 2026.

1 critical 1 high 2 medium

Running Adirectory on your site? Check whether your installed version is affected.

Scan your site free

aDirectory <= 3.0.3 - Missing Authorization

medium

The aDirectory – WP Business Directory Plugin and Classified Ads Listings Directory plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.0.3. This makes it possible for authenticated attackers, with Subscriber-level access and...

CVSS:
4.3
Affected:
up to 3.0.3
Fixed in:
3.0.4
Disclosed:
Jan 27, 2026

CVE-2025-67975 on NVD →

aDirectory – WP Business Directory Plugin and Classified Ads Listings Directory [adirectory] < 2.3.5

unknown

[en] The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the adqs_delete_listing() function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and...

Affected:
up to 2.3.5
Fixed in:
2.3.5
Disclosed:
Feb 12, 2025

CVE-2024-13541 on NVD →

aDirectory – WordPress Directory Listing Plugin <= 2.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion

medium

The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the adqs_delete_listing() function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and abov...

CVSS:
4.3
Affected:
up to 2.3
Fixed in:
2.3.5
Disclosed:
Feb 11, 2025

CVE-2024-13541 on NVD →

aDirectory – WP Business Directory Plugin and Classified Ads Listings Directory [adirectory] < 1.9

unknown

<p>WordPress aDirectory Plugin <= 1.6.5 is vulnerable to PHP Object Injection</p><p>Software: aDirectory</p><p>Fixed in version 1.9 </p><p>Affected Version <= 1.6.5</p>

Affected:
up to 1.9
Fixed in:
1.9
Disclosed:
Jan 21, 2025

aDirectory – WordPress Directory Listing Plugin <= 1.6.5 - Unauthenticated PHP Object Injection

high

The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.5 via deserialization of untrusted input from the 'carousel_settings' attribute in the 'adqs_taxonomies' shortcode. This makes it possible for unauthenticated attacker...

CVSS:
7.5
Affected:
up to 1.6.5
Fixed in:
1.9
Disclosed:
Jan 20, 2025

aDirectory <= 1.3 - Unauthenticated Arbitrary File Upload

critical

The aDirectory – Directory Listing WordPress Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remo...

CVSS:
9.8
Affected:
up to 1.3
Fixed in:
1.3.1
Disclosed:
Oct 24, 2024

CVE-2024-50420 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database