PLUGIN SECURITY

Is Directorist Booking safe?

Build any type of directory website such as a business directory, job directory, classifieds directory, and more with this WordPress directory plugin.

What this plugin does

  • Slug: directorist-booking
  • Author: wpWax
  • 20000+ active installs
  • 92/100 rating (697 reviews on wordpress.org)
  • 1269257 all-time downloads
  • On WordPress.org since 2017-08-27

business directoryclassifiedsdirectorydirectory pluginlistings

Maintenance status

  • Latest known version: 8.9.3
  • Last updated: 2026-09-02 8:46am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+

Known vulnerabilities

2 known CVEs on file for Directorist Booking. Reported between 2026 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-49073 Directorist Booking [directorist-booking] < 3.0.4 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.5 < 3.0.4 3.0.4 2026-06-08 ✓ fixed in latest
Directorist Booking [directorist-booking] < 3.0.2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.3 < 3.0.2 3.0.2 2026-01-20 ✓ fixed in latest
CVE-2026-22336 Directorist Booking <= 2.4.1 - Unauthenticated SQL Injection Unknown not specified no fix on file

How to fix it

Keep Directorist Booking updated — 8.9.3 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

1 of the vulnerabilities above has no fixed version on file — there's no update that resolves it. Consider deactivating this plugin or switching to one of the alternatives below.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.