CVE-2026-59518
The Directorist: AI-Powered Business Directory, Listings & Classified Ads plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 8.8.2 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Source:
Wordfence
CVE-2026-39509
The Directorist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 8.5.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Source:
Wordfence
CVE-2025-68069
The Directorist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 8.6.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
Source:
Wordfence
CVE-2025-64250
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 8.6.6. This is due to insufficient validation on the redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
Source:
Wordfence
CVE-2025-12174
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'directorist_prepare_listings_export_file' and 'directorist_type_slug_change' AJAX actions in all versions up to, and including, 8.5.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export listing details and change the directorist slug.
Source:
CVE.org
CVE-2025-10488
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to arbitrary file move due to insufficient file path validation in the add_listing_action AJAX action in all versions up to, and including, 8.4.8. This makes it possible for unauthenticated attackers to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php).
Source:
CVE.org
CVE-2024-12041
The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including including usernames, email addresses, names, and more information about users.
Source:
CVE.org
CVE-2024-33929
The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.8.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Source:
Wordfence
+ 15 more known vulnerabilities
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-1322
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.8.5 |
Missing Authorization |
Medium
5.3
|
< 7.8.5
|
7.8.5 |
2024-02-12 |
—
|
|
CVE-2023-41798
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.7.2 |
Improper Neutralization of Formula Elements in a CSV File |
Medium
5.1
|
< 7.7.2
|
7.7.2 |
2023-09-05 |
—
|
|
CVE-2022-47150
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.7.2 |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 7.7.2
|
7.7.2 |
2023-09-04 |
—
|
|
CVE-2023-35052
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.5 |
Missing Authorization |
Medium
4.3
|
< 7.5.5
|
7.5.5 |
2023-06-13 |
—
|
|
CVE-2023-1888
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.5 |
Improper Input Validation |
High
8.8
|
< 7.5.5
|
7.5.5 |
2023-06-01 |
—
|
|
CVE-2023-1889
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.5 |
Authorization Bypass Through User-Controlled Key |
Medium
6.5
|
< 7.5.5
|
7.5.5 |
2023-06-01 |
—
|
|
CVE-2023-2252
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.4 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Low
2.7
|
< 7.5.4
|
7.5.4 |
2023-05-10 |
—
|
|
CVE-2022-3961
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.4.4 |
Missing Authorization |
Medium
6.5
|
< 7.4.4
|
7.4.4 |
2022-11-28 |
—
|
|
CVE-2022-3930
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.4.2.2 |
Authorization Bypass Through User-Controlled Key |
Medium
6.5
|
< 7.4.2.2
|
7.4.2.2 |
2022-11-21 |
—
|
|
CVE-2022-2376
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.3.1 |
Missing Authorization |
Medium
5.3
|
< 7.3.1
|
7.3.1 |
2022-08-10 |
—
|
|
CVE-2022-2377
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.3.0 |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 7.3.0
|
7.3.0 |
2022-07-26 |
—
|
|
CVE-2022-2046
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.2.3 |
Unrestricted Upload of File with Dangerous Type |
Medium
4.9
|
< 7.2.3
|
7.2.3 |
2022-07-18 |
—
|
|
CVE-2021-24981
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.0.6.2 |
Cross-Site Request Forgery (CSRF) |
High
7.5
|
< 7.0.6.2
|
7.0.6.2 |
2021-11-16 |
—
|
|
CVE-2025-1570
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.2 |
Weak Password Recovery Mechanism for Forgotten Password |
Critical
9.8
|
< 8.2
|
8.2 |
0000-00-00 |
—
|
|
CVE-2025-2224
|
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.3 |
Missing Authorization |
Medium
5.3
|
< 8.3
|
8.3 |
0000-00-00 |
—
|
CVE-2024-1322
Update the WordPress Directorist plugin to the latest available version (at least 7.8.5).
Lucio Sá discovered and reported this Broken Access Control vulnerability in WordPress Directorist Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 7.8.5.
Have additional information or questions about this entry? Get in touch.
Source:
Patchstack
CVE-2023-41798
No patched version is available.
Rafshanzani Suhada discovered and reported this CSV Injection vulnerability in WordPress Directorist Plugin. This could allow a malicious actor to craft malicious formulas to then exploit vulnerabilities in the spreadsheet software or to execute commands to gain access to the victim';s PC. This vulnerability has not been known to be fixed yet.
Source:
Patchstack
CVE-2022-47150
No patched version is available.
Lana Codes discovered and reported this Broken Access Control vulnerability in WordPress Directorist Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has not been known to be fixed yet.
Source:
Patchstack
CVE-2023-35052
Update the WordPress Directorist plugin to the latest available version (at least 7.5.5).
Rafshanzani Suhada discovered and reported this Arbitrary Content Deletion vulnerability in WordPress Directorist Plugin. This could allow a malicious actor to delete content from your website such as pictures, posts or pages. This vulnerability has been fixed in version 7.5.5.
Source:
Patchstack
CVE-2023-1888
Update the WordPress Directorist plugin to the latest available version (at least 7.5.5).
Alex Thomas discovered and reported this Privilege Escalation vulnerability in WordPress Directorist Plugin. This could allow a malicious actor to escalate their low privileged account to something with higher privileges. After this they could take full control of the website if high privileges are gained. This vulnerability has been fixed in version 7.5.5.
Source:
Patchstack
CVE-2023-1889
The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to improper validation and authorization checks within the listing_task function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete arbitrary posts. Please note CVE-2023-35052 appears to be a duplicate of this issue.
Source:
Wordfence
CVE-2023-2252
The Directorist for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.5.3 via the file parameter during CSV import. This allows administrator-level attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Source:
Wordfence
CVE-2022-3961
The Directorist for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 7.4.3. This can allow authenticated attackers, with subscriber-level permissions or higher, to extract sensitive system data.
Source:
Wordfence
CVE-2022-3930
The Directorist plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 7.4.2.1. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for subscriber-level attackers to change user passwords and potentially take over administrator accounts.
Source:
Wordfence
CVE-2022-2376
Unauthenticated Email Address Disclosure vulnerability discovered by Krzysztof Zając in WordPress Directorist plugin (versions <= 7.3.0).
Update the WordPress Directorist plugin to the latest available version (at least 7.3.1).
Source:
Patchstack
CVE-2022-2377
The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the send_announcement() function in versions up to, and including, 7.2.3. This makes it possible for authenticated attackers with subscriber level permissions to send arbitrary emails from the vulnerable WordPress site.
Source:
Wordfence
CVE-2022-2046
The Directorist plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the atbdp_download_file() AJAX action in versions up to, and including, 7.2.2. This makes it possible for authenticated attackers with administrative privileges to upload arbitrary files on the affected sites server which may make remote code execution possible. This only affects sites where administrator have been restricted in their uploading files capabilities.
Source:
Wordfence
CVE-2021-24981
The plugin was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.
This vulnerability was seen actively exploited by Sucuri in the wild for ransomware attacks.
Source:
WPScan
CVE-2025-1570
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 8.1. This is due to the directorist_generate_password_reset_pin_code() and reset_user_password() functions not having enough controls to prevent a successful brute force attack of the OTP to change a password, or verify that a password reset request came from an authorized user. This makes it possible for unauthenticated attackers to generate and brute force an OTP that makes it possible to change any users passwords, including an administrator.
Source:
Wordfence
CVE-2025-2224
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'parse_query' function in all versions up to, and including, 8.2. This makes it possible for unauthenticated attackers to update the post_status of any post to 'publish'.
Source:
Wordfence
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.