CVE Database /
CVE-2022-2046
CVE · Medium
CVE-2022-2046 — Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.2.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-2046
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.2.3 |
Unrestricted Upload of File with Dangerous Type |
Medium
4.9
|
< 7.2.3
|
7.2.3 |
2022-07-18 |
—
|
CVE-2022-2046
The Directorist WordPress plugin before version 7.2.3 contains a vulnerability in the atbdp_download_file() AJAX action that fails to properly validate uploaded file types, allowing authenticated administrators to upload arbitrary files to the server and potentially execute remote code. This issue specifically impacts installations where administrator file upload capabilities have been restricted, as the vulnerability bypasses those intended restrictions.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings