PLUGIN SECURITY
Is Directorist safe?
Build any type of directory website such as a business directory, job directory, classifieds directory, and more with this WordPress directory plugin.
What this plugin does
- Slug:
directorist - Author: wpWax
- 20000+ active installs
- 92/100 rating (697 reviews on wordpress.org)
- 1278253 all-time downloads
- On WordPress.org since 2017-08-27
business directoryclassifiedsdirectorydirectory pluginlistings
Maintenance status
- Latest known version: 8.9.3
- Last updated: 2026-09-02 8:46am GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
Known vulnerabilities
25 known CVEs on file for Directorist.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-84066 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.9 | Missing Authorization | Unknown | < 8.9 | 8.9 | 2026-09-04 | ✓ fixed in latest |
| CVE-2026-59518 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.8.3 | — | Critical 9.8 | < 8.8.3 | 8.8.3 | 2026-07-09 | ✓ fixed in latest |
| CVE-2026-77757 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.9.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Unknown | < 8.9.3 | 8.9.3 | 2026-07-09 | ✓ fixed in latest |
| CVE-2026-39509 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.6.1 | — | Medium 5.3 | < 8.6.1 | 8.6.1 | 2026-02-22 | ✓ fixed in latest |
| CVE-2025-68069 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.6.7 | Missing Authorization | High 7.1 | < 8.6.7 | 8.6.7 | 2026-01-27 | ✓ fixed in latest |
| CVE-2025-64250 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.6.7 | URL Redirection to Untrusted Site ('Open Redirect') | Medium 4.7 | < 8.6.7 | 8.6.7 | 2025-12-15 | ✓ fixed in latest |
| CVE-2025-12174 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.5.3 | Missing Authorization | Medium 6.5 | < 8.5.3 | 8.5.3 | 2025-11-18 | ✓ fixed in latest |
| CVE-2025-10488 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.4.9 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 8.1 | < 8.4.9 | 8.4.9 | 2025-10-24 | ✓ fixed in latest |
+ 19 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-12041 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.1 | Exposure of Private Personal Information to an Unauthorized Actor | Medium 5.3 | < 8.1 | 8.1 | 2025-01-31 | ✓ fixed in latest |
| CVE-2024-33929 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.9.0 | Missing Authorization | Medium 5.3 | < 7.9.0 | 7.9.0 | 2024-04-29 | ✓ fixed in latest |
| CVE-2024-1322 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.8.5 | Missing Authorization | Medium 5.3 | < 7.8.5 | 7.8.5 | 2024-02-12 | ✓ fixed in latest |
| CVE-2023-41798 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.7.2 | Improper Neutralization of Formula Elements in a CSV File | Medium 5.1 | < 7.7.2 | 7.7.2 | 2023-09-05 | ✓ fixed in latest |
| CVE-2022-47150 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.7.2 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 7.7.2 | 7.7.2 | 2023-09-04 | ✓ fixed in latest |
| CVE-2023-35052 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.5 | Missing Authorization | Medium 4.3 | < 7.5.5 | 7.5.5 | 2023-06-13 | ✓ fixed in latest |
| CVE-2023-1888 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.5 | Improper Input Validation | High 8.8 | < 7.5.5 | 7.5.5 | 2023-06-01 | ✓ fixed in latest |
| CVE-2023-1889 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.5 | Authorization Bypass Through User-Controlled Key | Medium 6.5 | < 7.5.5 | 7.5.5 | 2023-06-01 | ✓ fixed in latest |
| CVE-2023-2252 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.4 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Low 2.7 | < 7.5.4 | 7.5.4 | 2023-05-10 | ✓ fixed in latest |
| CVE-2022-3961 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.4.4 | Missing Authorization | Medium 6.5 | < 7.4.4 | 7.4.4 | 2022-11-28 | ✓ fixed in latest |
| CVE-2022-3930 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.4.2.2 | Authorization Bypass Through User-Controlled Key | Medium 6.5 | < 7.4.2.2 | 7.4.2.2 | 2022-11-21 | ✓ fixed in latest |
| CVE-2022-2376 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.3.1 | Missing Authorization | Medium 5.3 | < 7.3.1 | 7.3.1 | 2022-08-10 | ✓ fixed in latest |
| CVE-2022-2377 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.3.0 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 7.3.0 | 7.3.0 | 2022-07-26 | ✓ fixed in latest |
| CVE-2022-2046 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.2.3 | Unrestricted Upload of File with Dangerous Type | Medium 4.9 | < 7.2.3 | 7.2.3 | 2022-07-18 | ✓ fixed in latest |
| CVE-2021-24981 | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.0.6.2 | Cross-Site Request Forgery (CSRF) | High 7.5 | < 7.0.6.2 | 7.0.6.2 | 2021-11-16 | ✓ fixed in latest |
| — | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.2 | Weak Password Recovery Mechanism for Forgotten Password | Critical 9.8 | < 8.2 | 8.2 | 0000-00-00 | ✓ fixed in latest |
| — | Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.3 | Missing Authorization | Medium 5.3 | < 8.3 | 8.3 | 0000-00-00 | ✓ fixed in latest |
| CVE-2025-1570 | Directorist: AI-Powered Business Directory < 8.2 - Privilege Escalation and Account Takeover | — | Unknown | < 8.2 | 8.2 | — | ✓ fixed in latest |
| CVE-2025-2224 | Directorist < 8.3 - Missing Authorization to Unauthenticated Arbitrary Post Publishing | — | Unknown | < 8.3 | 8.3 | — | ✓ fixed in latest |
How to fix it
Keep Directorist updated — 8.9.3 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- GeoDirectory – WP Business Directory Plugin and Classified Listings Directory — 10000+ active installs — 96/100 (715) — max PHP <8.0
- HivePress – Business Directory, Listings & Classified Ads Plugin — 10000+ active installs — 98/100 (221) — max PHP 8.4
- Business Directory Plugin – Easy Listing & Member Directories for WordPress — 10000+ active installs — 92/100 (504) — max PHP 8.4
- Classified Listing – AI-Powered Classified ads & Business Directory — 9000+ active installs — 96/100 (138)
- Motors – Car Dealership & Classified Listings Plugin — 9000+ active installs — 90/100 (79)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.