VYPR

Directorist

by WordPress

Source repositories

CVEs (23)

  • CVE-2022-2377MedAug 22, 2022
    risk 0.21cvss 4.3epss 0.00

    The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing any authenticated users to send arbitrary emails on behalf of the blog

  • CVE-2023-2252LowJan 16, 2024
    risk 0.11cvss 2.7epss 0.01

    The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.

  • CVE-2026-59518CriJul 13, 2026
    risk 0.00cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.

Page 2 of 2