CVE · Medium

CVE-2024-12041 — Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-12041 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.1 Exposure of Private Personal Information to an Unauthorized Actor Medium 5.3 < 8.1 8.1 2025-01-31

CVE-2024-12041

The Directorist business directory plugin for WordPress through version 8.0.12 exposes sensitive user information through an unauthenticated REST API endpoint at /wp-json/directorist/v1/users/. Attackers without authentication can retrieve user details such as usernames, email addresses, and full names through this publicly accessible endpoint. This information disclosure vulnerability affects all versions up to and including 8.0.12.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.