CVE · Medium

CVE-2025-12174 — Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.5.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12174 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.5.3 Missing Authorization Medium 6.5 < 8.5.3 8.5.3 2025-11-18

CVE-2025-12174

The Directorist plugin's security has been compromised by a critical oversight affecting all versions prior to 8.5.3. Specifically, insufficient permission checks on two specific AJAX actions have created an opening for attackers with Subscriber level clearance or higher to execute unauthorized operations. This includes exporting sensitive listing data and modifying the directorist slug without proper authorization.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.