CVE Database /
CVE-2025-12174
CVE · Medium
CVE-2025-12174 — Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.5.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-12174
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.5.3 |
Missing Authorization |
Medium
6.5
|
< 8.5.3
|
8.5.3 |
2025-11-18 |
—
|
CVE-2025-12174
The Directorist plugin's security has been compromised by a critical oversight affecting all versions prior to 8.5.3. Specifically, insufficient permission checks on two specific AJAX actions have created an opening for attackers with Subscriber level clearance or higher to execute unauthorized operations. This includes exporting sensitive listing data and modifying the directorist slug without proper authorization.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings