WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Directorist safe?

Known vulnerabilities, PHP compatibility and safer alternatives for the Directorist WordPress plugin — checked against WP Clinic's local security database.

What this plugin does

  • Slug: directorist

Maintenance status

Known vulnerabilities

23 known CVEs on file for Directorist.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-59518 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.8.3 Critical 9.8 < 8.8.3 8.8.3 2026-07-09
CVE-2026-39509 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.6.1 Medium 5.3 < 8.6.1 8.6.1 2026-02-22
CVE-2025-68069 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.6.7 Missing Authorization High 7.1 < 8.6.7 8.6.7 2026-01-27
CVE-2025-64250 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.6.7 URL Redirection to Untrusted Site ('Open Redirect') Medium 4.7 < 8.6.7 8.6.7 2025-12-15
CVE-2025-12174 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.5.3 Missing Authorization Medium 6.5 < 8.5.3 8.5.3 2025-11-18
CVE-2025-10488 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.4.9 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 8.1 < 8.4.9 8.4.9 2025-10-24
CVE-2024-12041 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.1 Exposure of Private Personal Information to an Unauthorized Actor Medium 5.3 < 8.1 8.1 2025-01-31
CVE-2024-33929 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.9.0 Missing Authorization Medium 5.3 < 7.9.0 7.9.0 2024-04-29

CVE-2026-59518

The Directorist: AI-Powered Business Directory, Listings & Classified Ads plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 8.8.2 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

Source: Wordfence

CVE-2026-39509

The Directorist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 8.5.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Source: Wordfence

CVE-2025-68069

The Directorist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 8.6.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

Source: Wordfence

CVE-2025-64250

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 8.6.6. This is due to insufficient validation on the redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

Source: Wordfence

CVE-2025-12174

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'directorist_prepare_listings_export_file' and 'directorist_type_slug_change' AJAX actions in all versions up to, and including, 8.5.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export listing details and change the directorist slug.

Source: CVE.org

CVE-2025-10488

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to arbitrary file move due to insufficient file path validation in the add_listing_action AJAX action in all versions up to, and including, 8.4.8. This makes it possible for unauthenticated attackers to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php).

Source: CVE.org

CVE-2024-12041

The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including including usernames, email addresses, names, and more information about users.

Source: CVE.org

CVE-2024-33929

The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.8.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Source: Wordfence

+ 15 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1322 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.8.5 Missing Authorization Medium 5.3 < 7.8.5 7.8.5 2024-02-12
CVE-2023-41798 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.7.2 Improper Neutralization of Formula Elements in a CSV File Medium 5.1 < 7.7.2 7.7.2 2023-09-05
CVE-2022-47150 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.7.2 Cross-Site Request Forgery (CSRF) Medium 4.3 < 7.7.2 7.7.2 2023-09-04
CVE-2023-35052 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.5 Missing Authorization Medium 4.3 < 7.5.5 7.5.5 2023-06-13
CVE-2023-1888 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.5 Improper Input Validation High 8.8 < 7.5.5 7.5.5 2023-06-01
CVE-2023-1889 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.5 Authorization Bypass Through User-Controlled Key Medium 6.5 < 7.5.5 7.5.5 2023-06-01
CVE-2023-2252 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.4 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Low 2.7 < 7.5.4 7.5.4 2023-05-10
CVE-2022-3961 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.4.4 Missing Authorization Medium 6.5 < 7.4.4 7.4.4 2022-11-28
CVE-2022-3930 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.4.2.2 Authorization Bypass Through User-Controlled Key Medium 6.5 < 7.4.2.2 7.4.2.2 2022-11-21
CVE-2022-2376 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.3.1 Missing Authorization Medium 5.3 < 7.3.1 7.3.1 2022-08-10
CVE-2022-2377 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.3.0 Cross-Site Request Forgery (CSRF) Medium 4.3 < 7.3.0 7.3.0 2022-07-26
CVE-2022-2046 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.2.3 Unrestricted Upload of File with Dangerous Type Medium 4.9 < 7.2.3 7.2.3 2022-07-18
CVE-2021-24981 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.0.6.2 Cross-Site Request Forgery (CSRF) High 7.5 < 7.0.6.2 7.0.6.2 2021-11-16
CVE-2025-1570 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.2 Weak Password Recovery Mechanism for Forgotten Password Critical 9.8 < 8.2 8.2 0000-00-00
CVE-2025-2224 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.3 Missing Authorization Medium 5.3 < 8.3 8.3 0000-00-00

CVE-2024-1322

Update the WordPress Directorist plugin to the latest available version (at least 7.8.5). Lucio Sá discovered and reported this Broken Access Control vulnerability in WordPress Directorist Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 7.8.5. Have additional information or questions about this entry? Get in touch.

Source: Patchstack

CVE-2023-41798

No patched version is available. Rafshanzani Suhada discovered and reported this CSV Injection vulnerability in WordPress Directorist Plugin. This could allow a malicious actor to craft malicious formulas to then exploit vulnerabilities in the spreadsheet software or to execute commands to gain access to the victim';s PC. This vulnerability has not been known to be fixed yet.

Source: Patchstack

CVE-2022-47150

No patched version is available. Lana Codes discovered and reported this Broken Access Control vulnerability in WordPress Directorist Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has not been known to be fixed yet.

Source: Patchstack

CVE-2023-35052

Update the WordPress Directorist plugin to the latest available version (at least 7.5.5). Rafshanzani Suhada discovered and reported this Arbitrary Content Deletion vulnerability in WordPress Directorist Plugin. This could allow a malicious actor to delete content from your website such as pictures, posts or pages. This vulnerability has been fixed in version 7.5.5.

Source: Patchstack

CVE-2023-1888

Update the WordPress Directorist plugin to the latest available version (at least 7.5.5). Alex Thomas discovered and reported this Privilege Escalation vulnerability in WordPress Directorist Plugin. This could allow a malicious actor to escalate their low privileged account to something with higher privileges. After this they could take full control of the website if high privileges are gained. This vulnerability has been fixed in version 7.5.5.

Source: Patchstack

CVE-2023-1889

The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to improper validation and authorization checks within the listing_task function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete arbitrary posts. Please note CVE-2023-35052 appears to be a duplicate of this issue.

Source: Wordfence

CVE-2023-2252

The Directorist for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.5.3 via the file parameter during CSV import. This allows administrator-level attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

Source: Wordfence

CVE-2022-3961

The Directorist for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 7.4.3. This can allow authenticated attackers, with subscriber-level permissions or higher, to extract sensitive system data.

Source: Wordfence

CVE-2022-3930

The Directorist plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 7.4.2.1. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for subscriber-level attackers to change user passwords and potentially take over administrator accounts.

Source: Wordfence

CVE-2022-2376

Unauthenticated Email Address Disclosure vulnerability discovered by Krzysztof Zając in WordPress Directorist plugin (versions <= 7.3.0). Update the WordPress Directorist plugin to the latest available version (at least 7.3.1).

Source: Patchstack

CVE-2022-2377

The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the send_announcement() function in versions up to, and including, 7.2.3. This makes it possible for authenticated attackers with subscriber level permissions to send arbitrary emails from the vulnerable WordPress site.

Source: Wordfence

CVE-2022-2046

The Directorist plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the atbdp_download_file() AJAX action in versions up to, and including, 7.2.2. This makes it possible for authenticated attackers with administrative privileges to upload arbitrary files on the affected sites server which may make remote code execution possible. This only affects sites where administrator have been restricted in their uploading files capabilities.

Source: Wordfence

CVE-2021-24981

The plugin was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory. This vulnerability was seen actively exploited by Sucuri in the wild for ransomware attacks.

Source: WPScan

CVE-2025-1570

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 8.1. This is due to the directorist_generate_password_reset_pin_code() and reset_user_password() functions not having enough controls to prevent a successful brute force attack of the OTP to change a password, or verify that a password reset request came from an authorized user. This makes it possible for unauthenticated attackers to generate and brute force an OTP that makes it possible to change any users passwords, including an administrator.

Source: Wordfence

CVE-2025-2224

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'parse_query' function in all versions up to, and including, 8.2. This makes it possible for unauthenticated attackers to update the post_status of any post to 'publish'.

Source: Wordfence

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.