Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Directorist: AI-Powered Business Directory, Listings & Classified Ads — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Directorist: AI-Powered Business Directory, Listings & Classified Ads, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting the WordPress plugin Directorist: AI-Powered Business Directory, Listings & Classified Ads. It catalogs identified flaws within the software, covering security advisories and patch disclosures released over the past several years. Readers can use this resource to track the vendor’s historical response to security issues, analyze recurring weakness classes such as cross-site scripting or access control failures, and review the complete vulnerability history for this specific directory solution. The collection provides a consolidated view of past exploits and remediations, enabling security professionals to assess the long-term security posture of the application. By examining the documented weaknesses, organizations can identify patterns in implementation errors and understand the evolution of the plugin’s security landscape. This repository serves as a technical reference for developers and security analysts seeking to verify patches or conduct risk assessments based on prior incidents. The data presented focuses on publicly disclosed issues, offering transparency into the types of attacks that have impacted business directory platforms utilizing this plugin. Users can filter entries to gain insight into specific vulnerability categories, helping to prioritize remediation efforts in their own environments where this software is deployed.

Vendor: wpwax

CVE ID Title CVSS Severity Published
CVE-2026-84027 Directorist 8.9.1 - 8.9.4 - Subscriber+ Paid Order and Payment Record Forgery via REST Orders Endpoint - - 2026-09-23
CVE-2026-84046 Directorist < 8.9.5 - Subscriber+ SSRF via Avatar URL - - 2026-09-23
CVE-2026-84098 Directorist 3.1.0 - 8.9.4 - Subscriber+ Arbitrary Listing Deletion via remove_listing - - 2026-09-23
CVE-2026-84150 Directorist < 8.9.5 - Subscriber+ Cross-User Favorites Read and Write via REST Favorites Endpoint - - 2026-09-23
CVE-2026-84026 Directorist 8.1 - 8.9.4 - Unauthenticated Sensitive Data Disclosure via REST Users Endpoint - - 2026-09-23
CVE-2026-77766 Directorist 8.5 - 8.9.4 - Subscriber+ Order and Financial Record Disclosure via REST Orders Endpoint - - 2026-09-23
CVE-2026-84066 Directorist < 8.9 - Subscriber+ Arbitrary Post Meta Write via atbdp_post_attachment_upload - - 2026-09-04
CVE-2026-77757 Directorist 8.5 - 8.9.2 - Subscriber+ Arbitrary Image Move via REST v2 Listing Submission - - 2026-08-26
CVE-2025-12174 Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.5.2 - Missing Authorization to Authenticated (Subscriber+) Data Export and Slug Update CWE-862 6.5 Medium 2025-11-19
CVE-2025-10488 Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.4.8 - Authenticated (Subscriber+) Arbitrary File Move CWE-22 8.1 High 2025-10-25
CVE-2025-2224 Directorist <= 8.2 - Missing Authorization to Unauthenticated Arbitrary Post Publishing CWE-862 5.3 Medium 2025-03-25
CVE-2025-1570 Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.1 - Privilege Escalation and Account Takeover via Weak OTP CWE-640 8.1 High 2025-02-28
CVE-2024-12041 Directorist – AI-Powered WordPress Business Directory Plugin with Classified Ads Listings <= 8.0.12 - Unauthenticated User Information Exposure CWE-359 5.3 Medium 2025-02-01
CVE-2024-1322 Directorist <= 7.8.4 - Missing Authorization to Unauthenticated Settings Change CWE-862 5.3 Medium 2024-02-20
CVE-2023-1889 Directorist <= 7.5.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Post Deletion in listing_task CWE-639 6.5 Medium 2023-06-09
CVE-2023-1888 Directorist <= 7.5.4 - Authenticated (Subscriber+) Arbitrary User Password Reset to Privilege Escalation CWE-20 8.8 High 2023-06-09

All 16 known CVE vulnerabilities affecting Directorist: AI-Powered Business Directory, Listings & Classified Ads with full Chinese analysis, references, and POCs where available.