CVE · Critical

CVE-2026-59518 — Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.8.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-59518 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.8.3 Critical 9.8 < 8.8.3 8.8.3 2026-07-09

CVE-2026-59518

The Directorist WordPress plugin has a security flaw that allows attackers with subscriber-level access and above to inject malicious PHP objects into the application through untrusted input deserialization in versions up to 8.8.2. If other vulnerable plugins or themes are installed on the same system, this could potentially enable further attacks such as deleting files, accessing sensitive data, or executing code.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.