CVE · Medium

CVE-2025-64250 — Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.6.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-64250 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.6.7 URL Redirection to Untrusted Site ('Open Redirect') Medium 4.7 < 8.6.7 8.6.7 2025-12-15

CVE-2025-64250

The Directorist plugin for WordPress suffers from a security flaw in versions prior to 8.6.7, allowing unauthorized individuals to manipulate user navigation by exploiting the lack of thorough URL verification. This vulnerability enables attackers to redirect users to potentially hazardous websites if they can deceive them into taking specific actions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.