CVE · Medium

CVE-2022-2046 — Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.2.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2046 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.2.3 Unrestricted Upload of File with Dangerous Type Medium 4.9 < 7.2.3 7.2.3 2022-07-18

CVE-2022-2046

The Directorist WordPress plugin before version 7.2.3 contains a vulnerability in the atbdp_download_file() AJAX action that fails to properly validate uploaded file types, allowing authenticated administrators to upload arbitrary files to the server and potentially execute remote code. This issue specifically impacts installations where administrator file upload capabilities have been restricted, as the vulnerability bypasses those intended restrictions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.