CVE Database /
CVE-2023-2252
CVE · Low
CVE-2023-2252 — Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-2252
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.4 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Low
2.7
|
< 7.5.4
|
7.5.4 |
2023-05-10 |
—
|
CVE-2023-2252
The Directorist WordPress plugin through version 7.5.3 contains a local file inclusion vulnerability in its CSV import functionality via the file parameter, which allows administrators to include and execute arbitrary files on the server. Attackers with administrator privileges can leverage this flaw to run any PHP code present in uploaded files, potentially circumventing access restrictions, stealing confidential information, or executing malicious code when seemingly harmless file types such as images are uploaded and subsequently processed.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings