WP Clinic
Entrar Registrarse

CVE · High

CVE-2025-10488 — Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.4.9

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2025-10488 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.4.9 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Alta 8,1 < 8.4.9 8.4.9 2025-10-24

CVE-2025-10488

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to arbitrary file move due to insufficient file path validation in the add_listing_action AJAX action in all versions up to, and including, 8.4.8. This makes it possible for unauthenticated attackers to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Escanea tu sitio WordPress gratis

Sin registro, sin tarjeta de crédito — ingresa tu URL y obtén un informe de seguridad en segundos.