CVE Database /
CVE-2024-12041
CVE · Medium
CVE-2024-12041 — Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-12041
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.1 |
Exposure of Private Personal Information to an Unauthorized Actor |
Medium
5.3
|
< 8.1
|
8.1 |
2025-01-31 |
—
|
CVE-2024-12041
The Directorist business directory plugin for WordPress through version 8.0.12 exposes sensitive user information through an unauthenticated REST API endpoint at /wp-json/directorist/v1/users/. Attackers without authentication can retrieve user details such as usernames, email addresses, and full names through this publicly accessible endpoint. This information disclosure vulnerability affects all versions up to and including 8.0.12.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings