CVE Database /
CVE-2021-24981
CVE · High
CVE-2021-24981 — Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.0.6.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24981
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.0.6.2 |
Cross-Site Request Forgery (CSRF) |
High
7.5
|
< 7.0.6.2
|
7.0.6.2 |
2021-11-16 |
—
|
CVE-2021-24981
The Directorist plugin before version 7.0.6.2 contained a cross-site request forgery flaw that allowed attackers to upload arbitrary files, including malicious PHP shells, to the wp-content/plugins directory. This vulnerability was actively exploited in the wild by malicious actors to deploy ransomware. The lack of proper request verification made it possible for attackers to trick administrators into performing unintended file uploads that could lead to complete site compromise.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings