VYPR
Medium severity5.3NVD Advisory· Published Feb 29, 2024· Updated Apr 8, 2026

CVE-2024-1322

CVE-2024-1322

Description

The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 7.8.4. This makes it possible for unauthenticated attackers to recreate default pages and enable or disable monetization and change map provider.

Affected products

1
  • cpe:2.3:a:wpwax:directorist:*:*:*:*:*:wordpress:*:*
    Range: <7.8.5

Patches

1

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

3

News mentions

0

No linked articles in our index yet.