WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Directorist Booking safe?

Build any type of directory website such as a business directory, job directory, classifieds directory, and more with this WordPress directory plugin.

What this plugin does

  • Slug: directorist-booking
  • Author: wpWax
  • 20000+ active installs
  • 92/100 rating (694 reviews on wordpress.org)
  • 1235604 all-time downloads
  • On WordPress.org since 2017-08-27

business directoryclassifiedsdirectorydirectory pluginlistings

Maintenance status

  • Last updated: 2026-07-26 10:05am GMT
  • Tested up to WordPress: 7.0.2
  • Requires PHP: 7.4+

Known vulnerabilities

1 known CVE on file for Directorist Booking. Reported between 2026 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-49073 Directorist Booking [directorist-booking] < 3.0.4 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.5 < 3.0.4 3.0.4 2026-06-08
Directorist Booking [directorist-booking] < 3.0.2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.3 < 3.0.2 3.0.2 2026-01-20

CVE-2026-49073

The Booking (Reservation & Appointment) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Source: Wordfence

Directorist Booking [directorist-booking] < 3.0.2

The Directorist Booking plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Source: Wordfence

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.