plugin

Directorist Vulnerabilities

44 known security issues reported for the Directorist WordPress plugin. Most recent disclosed Jul 9, 2026.

9 high 13 medium 1 low

Running Directorist on your site? Check whether your installed version is affected.

Scan your site free

Directorist: AI-Powered Business Directory, Listings & Classified Ads <= 8.8.2 - Authenticated (Subscriber+) PHP Object Injection

high

The Directorist: AI-Powered Business Directory, Listings & Classified Ads plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 8.8.2 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP...

CVSS:
7.5
Affected:
up to 8.8.2
Fixed in:
8.8.3
Disclosed:
Jul 9, 2026

CVE-2026-59518 on NVD →

Directorist <= 8.5.10 - Missing Authorization

medium

The Directorist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 8.5.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 8.5.10
Fixed in:
8.6.1
Disclosed:
Feb 22, 2026

CVE-2026-39509 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] <= 8.5.10 (unfixed)

unknown

[en] Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through <= 8.5.10.

Affected:
up to 8.5.10
Fix:
No patched version reported
Disclosed:
Feb 20, 2026

CVE-2025-68069 on NVD →

Directorist <= 8.6.6 - Missing Authorization

medium

The Directorist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 8.6.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 8.6.6
Fixed in:
8.6.7
Disclosed:
Jan 27, 2026

CVE-2025-68069 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] <= 8.5.6 (unfixed)

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wpWax Directorist directorist allows Phishing.This issue affects Directorist: from n/a through <= 8.5.6.

Affected:
up to 8.5.6
Fix:
No patched version reported
Disclosed:
Dec 16, 2025

CVE-2025-64250 on NVD →

Directorist <= 8.6.6 - Unauthenticated Open Redirect

medium

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 8.6.6. This is due to insufficient validation on the redirect url supplied. This makes it possible for unauthenticated attackers to redirect users...

CVSS:
5.8
Affected:
up to 8.6.6
Fixed in:
8.6.7
Disclosed:
Dec 15, 2025

CVE-2025-64250 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 8.5.3

unknown

[en] The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'directorist_prepare_listings_export_file' and 'directorist_type_slug_change' AJAX actions in all versions up to, and including, 8.5....

Affected:
up to 8.5.3
Fixed in:
8.5.3
Disclosed:
Nov 19, 2025

CVE-2025-12174 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.5.2 - Missing Authorization to Authenticated (Subscriber+) Data Export and Slug Update

medium

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'directorist_prepare_listings_export_file' and 'directorist_type_slug_change' AJAX actions in all versions up to, and including, 8.5.2. Th...

CVSS:
6.5
Affected:
up to 8.5.2
Fixed in:
8.5.3
Disclosed:
Nov 18, 2025

CVE-2025-12174 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 8.4.9

unknown

[en] The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to arbitrary file move due to insufficient file path validation in the add_listing_action AJAX action in all versions up to, and including, 8.4.8. This makes it possible for unauthenticated attacke...

Affected:
up to 8.4.9
Fixed in:
8.4.9
Disclosed:
Oct 25, 2025

CVE-2025-10488 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.4.8 - Authenticated (Subscriber+) Arbitrary File Move

high

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to arbitrary file move due to insufficient file path validation in the add_listing_action AJAX action in all versions up to, and including, 8.4.8. This makes it possible for unauthenticated attackers to...

CVSS:
8.1
Affected:
up to 8.4.8
Fixed in:
8.4.9
Disclosed:
Oct 24, 2025

CVE-2025-10488 on NVD →

Directorist <= 8.2 - Missing Authorization to Unauthenticated Arbitrary Post Publishing

medium

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'parse_query' function in all versions up to, and including, 8.2. This makes it possible for unauthenticated att...

CVSS:
5.3
Affected:
up to 8.2
Fixed in:
8.3
Disclosed:
Mar 24, 2025

CVE-2025-2224 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.1 - Privilege Escalation and Account Takeover via Weak OTP

high

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 8.1. This is due to the directorist_generate_password_reset_pin_code() and reset_user_password() functions not having e...

CVSS:
8.1
Affected:
up to 8.1
Fixed in:
8.2
Disclosed:
Feb 27, 2025

CVE-2025-1570 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 8.1

unknown

[en] The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ endpoint. This makes it possible for unauthenticated attackers to extract sensi...

Affected:
up to 8.1
Fixed in:
8.1
Disclosed:
Feb 1, 2025

CVE-2024-12041 on NVD →

Directorist – AI-Powered WordPress Business Directory Plugin with Classified Ads Listings <= 8.0.12 - Unauthenticated User Information Exposure

medium

The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ endpoint. This makes it possible for unauthenticated attackers to extract sensitive...

CVSS:
5.3
Affected:
up to 8.0.12
Fixed in:
8.1
Disclosed:
Jan 31, 2025

CVE-2024-12041 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 7.5.5

unknown

[en] Missing Authorization vulnerability in wpWax - WP Business Directory Plugin and Classified Listings Directory Directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through 7.5.4.

Affected:
up to 7.5.5
Fixed in:
7.5.5
Disclosed:
Dec 13, 2024

CVE-2023-35052 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 7.9.0

unknown

[en] Missing Authorization vulnerability in wpWax Directorist.This issue affects Directorist: from n/a through 7.8.6.

Affected:
up to 7.9.0
Fixed in:
7.9.0
Disclosed:
May 3, 2024

CVE-2024-33929 on NVD →

Directorist <= 7.8.6 - Missing Authorization

medium

The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.8.6. This makes it possible for unauthenticated attackers to perform an unauthorized action...

CVSS:
5.3
Affected:
up to 7.8.6
Fixed in:
7.9.0
Disclosed:
Apr 29, 2024

CVE-2024-33929 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 7.8.5

unknown

[en] The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 7.8.4. This makes it possible for unauthenticated attacke...

Affected:
up to 7.8.5
Fixed in:
7.8.5
Disclosed:
Feb 20, 2024

CVE-2024-1322 on NVD →

Directorist <= 7.8.4 - Missing Authorization to Unauthenticated Settings Change

medium

The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 7.8.4. This makes it possible for unauthenticated attackers to...

CVSS:
5.3
Affected:
up to 7.8.4
Fixed in:
7.8.5
Disclosed:
Feb 12, 2024

CVE-2024-1322 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 7.5.4

unknown

[en] The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.

Affected:
up to 7.5.4
Fixed in:
7.5.4
Disclosed:
Jan 16, 2024

CVE-2023-2252 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 7.7.2

unknown

[en] Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Directory Plugin with Classified Ads Listing.This issue affects Directorist – WordPress Business Directory Plugin with Classified Ads Listings: from n/a through 7.7.1.

Affected:
up to 7.7.2
Fixed in:
7.7.2
Disclosed:
Nov 7, 2023

CVE-2023-41798 on NVD →

Directorist <= 7.7.1 - CSV Injection

low

The Directorist plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 7.7.1. This allows editor-level and above attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable co...

CVSS:
3.8
Affected:
up to 7.7.1
Fixed in:
7.7.2
Disclosed:
Sep 5, 2023

CVE-2023-41798 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 7.5.5

unknown

[en] The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to improper validation and authorization checks within the listing_task function. This makes it possible for authenticated attackers, with subscriber-level permissions and...

Affected:
up to 7.5.5
Fixed in:
7.5.5
Disclosed:
Jun 9, 2023

CVE-2023-1889 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 7.5.5

unknown

[en] The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack of validation checks within login.php. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset the password of an a...

Affected:
up to 7.5.5
Fixed in:
7.5.5
Disclosed:
Jun 9, 2023

CVE-2023-1888 on NVD →

Directorist <= 7.5.4 - Authenticated (Subscriber+) Arbitrary User Password Reset to Privilege Escalation

high

The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack of validation checks within login.php. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset the password of an arbitr...

CVSS:
8.8
Affected:
up to 7.5.4
Fixed in:
7.5.5
Disclosed:
Jun 1, 2023

CVE-2023-1888 on NVD →

Directorist <= 7.5.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Post Deletion in listing_task

medium

The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to improper validation and authorization checks within the listing_task function. This makes it possible for authenticated attackers, with subscriber-level permissions and above...

CVSS:
6.5
Affected:
up to 7.5.4
Fixed in:
7.5.5
Disclosed:
Jun 1, 2023

CVE-2023-1889 on NVD →

Directorist <= 7.5.3 - Authenticated (Administrator+) Local File Inclusion

high

The Directorist for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.5.3 via the file parameter during CSV import. This allows administrator-level attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to...

CVSS:
7.2
Affected:
up to 7.5.3
Fixed in:
7.5.4
Disclosed:
May 10, 2023

CVE-2023-2252 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 7.4.4

unknown

[en] The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessing sensitive system information.

Affected:
up to 7.4.4
Fixed in:
7.4.4
Disclosed:
Dec 19, 2022

CVE-2022-3961 on NVD →

Appsero <= 1.2.1 - Missing Authorization

medium

The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with subscriber-level permissio...

CVSS:
4.3
Affected:
up to 7.7.1
Fixed in:
7.7.2
Disclosed:
Dec 16, 2022

Appsero <= 1.2.0 - Cross-Site Request Forgery

medium

The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function inten...

CVSS:
4.3
Affected:
up to 7.7.1
Fixed in:
7.7.2
Disclosed:
Dec 14, 2022

CVE-2022-47150 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 7.4.2.2

unknown

[en] The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.

Affected:
up to 7.4.2.2
Fixed in:
7.4.2.2
Disclosed:
Dec 12, 2022

CVE-2022-3930 on NVD →

Directorist <= 7.4.3 - Authenticated (Subscriber+) Sensitive Information Disclosure

medium

The Directorist for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 7.4.3. This can allow authenticated attackers, with subscriber-level permissions or higher, to extract sensitive system data.

CVSS:
4.3
Affected:
up to 7.4.3
Fixed in:
7.4.4
Disclosed:
Nov 28, 2022

CVE-2022-3961 on NVD →

Directorist <= 7.4.2.1 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Change

high

The Directorist plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 7.4.2.1. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for subscriber-level attackers...

CVSS:
8.8
Affected:
up to 7.4.2.1
Fixed in:
7.4.2.2
Disclosed:
Nov 21, 2022

CVE-2022-3930 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 7.3.1

unknown

[en] The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users

Affected:
up to 7.3.1
Fixed in:
7.3.1
Disclosed:
Sep 5, 2022

CVE-2022-2376 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 7.3.0

unknown

[en] The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing any authenticated users to send arbitrary emails on behalf of the blog

Affected:
up to 7.3.0
Fixed in:
7.3.0
Disclosed:
Aug 22, 2022

CVE-2022-2377 on NVD →

Directorist <= 7.3.0 - Sensitive Information Disclosure

high

The plugin Directorist for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 7.3.0. This could allow unauthenticated attackers to extract sensitive user data such as emails.

CVSS:
7.5
Affected:
up to 7.3.0
Fixed in:
7.3.1
Disclosed:
Aug 10, 2022

CVE-2022-2376 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 7.2.3

unknown

[en] The Directorist WordPress plugin before 7.2.3 allows administrators to download other plugins from the same vendor directly to the site, but does not check the URL domain it gets the zip files from. This could allow administrators to run code on the server, which is a problem in multisite configurations.

Affected:
up to 7.2.3
Fixed in:
7.2.3
Disclosed:
Aug 8, 2022

CVE-2022-2046 on NVD →

Directorist – WordPress Business Directory Plugin with Classified Ads Listings <= 7.2.3 - Missing Authorization

medium

The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the send_announcement() function in versions up to, and including, 7.2.3. This makes it possible for authenticated attackers with subscriber...

CVSS:
6.3
Affected:
up to 7.2.3
Fixed in:
7.3.0
Disclosed:
Jul 26, 2022

CVE-2022-2377 on NVD →

Directorist <= 7.2.2 - Authenticated (Admin+) Arbitrary File Upload

high

The Directorist plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the atbdp_download_file() AJAX action in versions up to, and including, 7.2.2. This makes it possible for authenticated attackers with administrative privileges to upload arbitrary files on the affected...

CVSS:
7.2
Affected:
up to 7.2.2
Fixed in:
7.2.3
Disclosed:
Jul 18, 2022

CVE-2022-2046 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 7.0.6.2

unknown

[en] The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.

Affected:
up to 7.0.6.2
Fixed in:
7.0.6.2
Disclosed:
Dec 21, 2021

CVE-2021-24981 on NVD →

Directorist <= 7.0.6.1 - Cross-Site Request Forgery to Arbitrary File Upload

high

The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.

CVSS:
8.8
Affected:
up to 7.0.6.1
Fixed in:
7.0.6.2
Disclosed:
Nov 16, 2021

CVE-2021-24981 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 7.7.2

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 7.7.2
Fixed in:
7.7.2

CVE-2022-47150 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 8.2

unknown
Affected:
up to 8.2
Fixed in:
8.2

CVE-2025-1570 on NVD →

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings [directorist] < 8.3

unknown
Affected:
up to 8.3
Fixed in:
8.3

CVE-2025-2224 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database