CVE-2026-59518
The Directorist: AI-Powered Business Directory, Listings & Classified Ads plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 8.8.2 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-39509
The Directorist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 8.5.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-68069
The Directorist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 8.6.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-64250
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 8.6.6. This is due to insufficient validation on the redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-12174
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'directorist_prepare_listings_export_file' and 'directorist_type_slug_change' AJAX actions in all versions up to, and including, 8.5.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export listing details and change the directorist slug.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2025-10488
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to arbitrary file move due to insufficient file path validation in the add_listing_action AJAX action in all versions up to, and including, 8.4.8. This makes it possible for unauthenticated attackers to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-12041
The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including including usernames, email addresses, names, and more information about users.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-33929
The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.8.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
+ 15 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-1322
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.8.5 |
Falta de control de autorización |
Media
5,3
|
< 7.8.5
|
7.8.5 |
2024-02-12 |
—
|
|
CVE-2023-41798
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.7.2 |
Neutralización incorrecta de elementos de fórmula en un archivo CSV (CSV Injection) |
Media
5,1
|
< 7.7.2
|
7.7.2 |
2023-09-05 |
—
|
|
CVE-2022-47150
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.7.2 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 7.7.2
|
7.7.2 |
2023-09-04 |
—
|
|
CVE-2023-35052
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.5 |
Falta de control de autorización |
Media
4,3
|
< 7.5.5
|
7.5.5 |
2023-06-13 |
—
|
|
CVE-2023-1888
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.5 |
Validación incorrecta de la entrada |
Alta
8,8
|
< 7.5.5
|
7.5.5 |
2023-06-01 |
—
|
|
CVE-2023-1889
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.5 |
Elusión de autorización mediante una clave controlada por el usuario |
Media
6,5
|
< 7.5.5
|
7.5.5 |
2023-06-01 |
—
|
|
CVE-2023-2252
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.4 |
Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) |
Baja
2,7
|
< 7.5.4
|
7.5.4 |
2023-05-10 |
—
|
|
CVE-2022-3961
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.4.4 |
Falta de control de autorización |
Media
6,5
|
< 7.4.4
|
7.4.4 |
2022-11-28 |
—
|
|
CVE-2022-3930
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.4.2.2 |
Elusión de autorización mediante una clave controlada por el usuario |
Media
6,5
|
< 7.4.2.2
|
7.4.2.2 |
2022-11-21 |
—
|
|
CVE-2022-2376
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.3.1 |
Falta de control de autorización |
Media
5,3
|
< 7.3.1
|
7.3.1 |
2022-08-10 |
—
|
|
CVE-2022-2377
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.3.0 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 7.3.0
|
7.3.0 |
2022-07-26 |
—
|
|
CVE-2022-2046
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.2.3 |
Carga de archivos sin restricción de tipo peligroso |
Media
4,9
|
< 7.2.3
|
7.2.3 |
2022-07-18 |
—
|
|
CVE-2021-24981
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.0.6.2 |
Falsificación de petición en sitios cruzados (CSRF) |
Alta
7,5
|
< 7.0.6.2
|
7.0.6.2 |
2021-11-16 |
—
|
|
CVE-2025-1570
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.2 |
Mecanismo débil de recuperación de contraseña olvidada |
Crítica
9,8
|
< 8.2
|
8.2 |
0000-00-00 |
—
|
|
CVE-2025-2224
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.3 |
Falta de control de autorización |
Media
5,3
|
< 8.3
|
8.3 |
0000-00-00 |
—
|
CVE-2024-1322
Update the WordPress Directorist plugin to the latest available version (at least 7.8.5).
Lucio Sá discovered and reported this Broken Access Control vulnerability in WordPress Directorist Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 7.8.5.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-41798
No patched version is available.
Rafshanzani Suhada discovered and reported this CSV Injection vulnerability in WordPress Directorist Plugin. This could allow a malicious actor to craft malicious formulas to then exploit vulnerabilities in the spreadsheet software or to execute commands to gain access to the victim';s PC. This vulnerability has not been known to be fixed yet.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2022-47150
No patched version is available.
Lana Codes discovered and reported this Broken Access Control vulnerability in WordPress Directorist Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has not been known to be fixed yet.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-35052
Update the WordPress Directorist plugin to the latest available version (at least 7.5.5).
Rafshanzani Suhada discovered and reported this Arbitrary Content Deletion vulnerability in WordPress Directorist Plugin. This could allow a malicious actor to delete content from your website such as pictures, posts or pages. This vulnerability has been fixed in version 7.5.5.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-1888
Update the WordPress Directorist plugin to the latest available version (at least 7.5.5).
Alex Thomas discovered and reported this Privilege Escalation vulnerability in WordPress Directorist Plugin. This could allow a malicious actor to escalate their low privileged account to something with higher privileges. After this they could take full control of the website if high privileges are gained. This vulnerability has been fixed in version 7.5.5.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-1889
The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to improper validation and authorization checks within the listing_task function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete arbitrary posts. Please note CVE-2023-35052 appears to be a duplicate of this issue.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-2252
The Directorist for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.5.3 via the file parameter during CSV import. This allows administrator-level attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-3961
The Directorist for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 7.4.3. This can allow authenticated attackers, with subscriber-level permissions or higher, to extract sensitive system data.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-3930
The Directorist plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 7.4.2.1. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for subscriber-level attackers to change user passwords and potentially take over administrator accounts.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-2376
Unauthenticated Email Address Disclosure vulnerability discovered by Krzysztof Zając in WordPress Directorist plugin (versions <= 7.3.0).
Update the WordPress Directorist plugin to the latest available version (at least 7.3.1).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2022-2377
The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the send_announcement() function in versions up to, and including, 7.2.3. This makes it possible for authenticated attackers with subscriber level permissions to send arbitrary emails from the vulnerable WordPress site.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-2046
The Directorist plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the atbdp_download_file() AJAX action in versions up to, and including, 7.2.2. This makes it possible for authenticated attackers with administrative privileges to upload arbitrary files on the affected sites server which may make remote code execution possible. This only affects sites where administrator have been restricted in their uploading files capabilities.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2021-24981
The plugin was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.
This vulnerability was seen actively exploited by Sucuri in the wild for ransomware attacks.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
CVE-2025-1570
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 8.1. This is due to the directorist_generate_password_reset_pin_code() and reset_user_password() functions not having enough controls to prevent a successful brute force attack of the OTP to change a password, or verify that a password reset request came from an authorized user. This makes it possible for unauthenticated attackers to generate and brute force an OTP that makes it possible to change any users passwords, including an administrator.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-2224
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'parse_query' function in all versions up to, and including, 8.2. This makes it possible for unauthenticated attackers to update the post_status of any post to 'publish'.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.