CVE · Low

CVE-2023-2252 — Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-2252 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.4 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Low 2.7 < 7.5.4 7.5.4 2023-05-10

CVE-2023-2252

The Directorist WordPress plugin through version 7.5.3 contains a local file inclusion vulnerability in its CSV import functionality via the file parameter, which allows administrators to include and execute arbitrary files on the server. Attackers with administrator privileges can leverage this flaw to run any PHP code present in uploaded files, potentially circumventing access restrictions, stealing confidential information, or executing malicious code when seemingly harmless file types such as images are uploaded and subsequently processed.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.