Resources /
WordPress Plugins /
Directorist Booking
PLUGIN SECURITY
Is Directorist Booking safe?
Build any type of directory website such as a business directory, job directory, classifieds directory, and more with this WordPress directory plugin.
What this plugin does
- Slug:
directorist-booking
- Author: wpWax
- 20000+ active installs
- 92/100 rating (694 reviews on wordpress.org)
- 1235604 all-time downloads
- On WordPress.org since 2017-08-27
business directoryclassifiedsdirectorydirectory pluginlistings
Maintenance status
- Last updated: 2026-07-26 10:05am GMT
- Tested up to WordPress: 7.0.2
- Requires PHP: 7.4+
Known vulnerabilities
1 known CVE on file for Directorist Booking.
Reported between 2026 and 2026.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-49073
|
Directorist Booking [directorist-booking] < 3.0.4 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
8.5
|
< 3.0.4
|
3.0.4 |
2026-06-08 |
—
|
|
—
|
Directorist Booking [directorist-booking] < 3.0.2 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Critical
9.3
|
< 3.0.2
|
3.0.2 |
2026-01-20 |
—
|
CVE-2026-49073
The Booking (Reservation & Appointment) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Source:
Wordfence
Directorist Booking [directorist-booking] < 3.0.2
The Directorist Booking plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Source:
Wordfence
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.