📦 Directorist

by Wpwax

🔍 What is Directorist?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-1570

HIGH CVSS 8.1 Feb 28, 2025

This vulnerability allows unauthenticated attackers to brute-force OTP codes and reset passwords for any user, including administrators, in the Directorist WordPress plugin. All WordPress sites using ...

CVE-2023-41798

HIGH CVSS 8.8 Nov 7, 2023

This CVE describes a CSV injection vulnerability in the Directorist WordPress plugin. Attackers can embed malicious formulas in CSV files that execute when opened in spreadsheet applications like Exce...

CVE-2023-1888

HIGH CVSS 8.8 Jun 9, 2023

The Directorist WordPress plugin up to version 7.5.4 contains an authentication bypass vulnerability that allows authenticated attackers with subscriber-level permissions or higher to reset any user's...

CVE-2021-24981

HIGH CVSS 7.5 Dec 21, 2021

The Directorist WordPress plugin before version 7.0.6.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to trick authenticated administrators into uploading arbitrary ...

CVE-2024-12041

MEDIUM CVSS 5.3 Feb 1, 2025

This vulnerability allows unauthenticated attackers to access sensitive user information through the Directorist WordPress plugin's REST API endpoint. All WordPress sites using Directorist plugin vers...