Directorist
by WordPress
Source repositories
CVEs (23)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-2377 | Med | 0.21 | 4.3 | 0.00 | Aug 22, 2022 | The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing any authenticated users to send arbitrary emails on behalf of the blog | ||
| CVE-2023-2252 | Low | 0.11 | 2.7 | 0.01 | Jan 16, 2024 | The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files. | ||
| CVE-2026-59518 | Cri | 0.00 | 9.8 | 0.01 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2. |
- risk 0.21cvss 4.3epss 0.00
The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing any authenticated users to send arbitrary emails on behalf of the blog
- risk 0.11cvss 2.7epss 0.01
The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.
- risk 0.00cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.
Page 2 of 2