PLUGIN SECURITY

Is Directorist safe?

Build any type of directory website such as a business directory, job directory, classifieds directory, and more with this WordPress directory plugin.

What this plugin does

  • Slug: directorist
  • Author: wpWax
  • 20000+ active installs
  • 92/100 rating (697 reviews on wordpress.org)
  • 1278253 all-time downloads
  • On WordPress.org since 2017-08-27

business directoryclassifiedsdirectorydirectory pluginlistings

Maintenance status

  • Latest known version: 8.9.3
  • Last updated: 2026-09-02 8:46am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+

Known vulnerabilities

25 known CVEs on file for Directorist.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-84066 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.9 Missing Authorization Unknown < 8.9 8.9 2026-09-04 ✓ fixed in latest
CVE-2026-59518 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.8.3 Critical 9.8 < 8.8.3 8.8.3 2026-07-09 ✓ fixed in latest
CVE-2026-77757 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.9.3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Unknown < 8.9.3 8.9.3 2026-07-09 ✓ fixed in latest
CVE-2026-39509 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.6.1 Medium 5.3 < 8.6.1 8.6.1 2026-02-22 ✓ fixed in latest
CVE-2025-68069 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.6.7 Missing Authorization High 7.1 < 8.6.7 8.6.7 2026-01-27 ✓ fixed in latest
CVE-2025-64250 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.6.7 URL Redirection to Untrusted Site ('Open Redirect') Medium 4.7 < 8.6.7 8.6.7 2025-12-15 ✓ fixed in latest
CVE-2025-12174 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.5.3 Missing Authorization Medium 6.5 < 8.5.3 8.5.3 2025-11-18 ✓ fixed in latest
CVE-2025-10488 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.4.9 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 8.1 < 8.4.9 8.4.9 2025-10-24 ✓ fixed in latest
+ 19 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-12041 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.1 Exposure of Private Personal Information to an Unauthorized Actor Medium 5.3 < 8.1 8.1 2025-01-31 ✓ fixed in latest
CVE-2024-33929 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.9.0 Missing Authorization Medium 5.3 < 7.9.0 7.9.0 2024-04-29 ✓ fixed in latest
CVE-2024-1322 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.8.5 Missing Authorization Medium 5.3 < 7.8.5 7.8.5 2024-02-12 ✓ fixed in latest
CVE-2023-41798 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.7.2 Improper Neutralization of Formula Elements in a CSV File Medium 5.1 < 7.7.2 7.7.2 2023-09-05 ✓ fixed in latest
CVE-2022-47150 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.7.2 Cross-Site Request Forgery (CSRF) Medium 4.3 < 7.7.2 7.7.2 2023-09-04 ✓ fixed in latest
CVE-2023-35052 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.5 Missing Authorization Medium 4.3 < 7.5.5 7.5.5 2023-06-13 ✓ fixed in latest
CVE-2023-1888 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.5 Improper Input Validation High 8.8 < 7.5.5 7.5.5 2023-06-01 ✓ fixed in latest
CVE-2023-1889 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.5 Authorization Bypass Through User-Controlled Key Medium 6.5 < 7.5.5 7.5.5 2023-06-01 ✓ fixed in latest
CVE-2023-2252 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.5.4 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Low 2.7 < 7.5.4 7.5.4 2023-05-10 ✓ fixed in latest
CVE-2022-3961 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.4.4 Missing Authorization Medium 6.5 < 7.4.4 7.4.4 2022-11-28 ✓ fixed in latest
CVE-2022-3930 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.4.2.2 Authorization Bypass Through User-Controlled Key Medium 6.5 < 7.4.2.2 7.4.2.2 2022-11-21 ✓ fixed in latest
CVE-2022-2376 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.3.1 Missing Authorization Medium 5.3 < 7.3.1 7.3.1 2022-08-10 ✓ fixed in latest
CVE-2022-2377 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.3.0 Cross-Site Request Forgery (CSRF) Medium 4.3 < 7.3.0 7.3.0 2022-07-26 ✓ fixed in latest
CVE-2022-2046 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.2.3 Unrestricted Upload of File with Dangerous Type Medium 4.9 < 7.2.3 7.2.3 2022-07-18 ✓ fixed in latest
CVE-2021-24981 Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 7.0.6.2 Cross-Site Request Forgery (CSRF) High 7.5 < 7.0.6.2 7.0.6.2 2021-11-16 ✓ fixed in latest
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.2 Weak Password Recovery Mechanism for Forgotten Password Critical 9.8 < 8.2 8.2 0000-00-00 ✓ fixed in latest
Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] < 8.3 Missing Authorization Medium 5.3 < 8.3 8.3 0000-00-00 ✓ fixed in latest
CVE-2025-1570 Directorist: AI-Powered Business Directory < 8.2 - Privilege Escalation and Account Takeover Unknown < 8.2 8.2 ✓ fixed in latest
CVE-2025-2224 Directorist < 8.3 - Missing Authorization to Unauthenticated Arbitrary Post Publishing Unknown < 8.3 8.3 ✓ fixed in latest

How to fix it

Keep Directorist updated — 8.9.3 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.