Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

WordPress security records

WordPress Vulnerability Listing

Filter Production Feed records and inspect affected software, version ranges, severity, patch information and source attribution without opening separate UUID pages.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

Clear filters

23 vulnerability records

HighCVE-2026-59518

Directorist: AI-Powered Business Directory, Listings & Classified Ads <= 8.8.2 - Authenticated (Subscriber+) PHP Object Injection

Affected versions: *-8.8.2

Vulnerability type: CWE-502 Deserialization of Untrusted Data

Affected software, patched versions and attribution

The Directorist: AI-Powered Business Directory, Listings & Classified Ads plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 8.8.2 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-8.8.2

Patched versions: 8.8.3

Researcher credit: dutafi

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
July 9, 2026
CVSS
7.5
MediumCVE-2026-39509

Directorist <= 8.5.10 - Missing Authorization

Affected versions: *-8.5.10

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The Directorist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 8.5.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-8.5.10

Patched versions: 8.6.1

Researcher credit: johska

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
February 22, 2026
CVSS
5.3
MediumCVE-2025-68069

Directorist <= 8.6.6 - Missing Authorization

Affected versions: *-8.6.6

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The Directorist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 8.6.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-8.6.6

Patched versions: 8.6.7

Researcher credit: daroo

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
January 27, 2026
CVSS
4.3
MediumCVE-2025-64250

Directorist <= 8.6.6 - Unauthenticated Open Redirect

Affected versions: *-8.6.6

Vulnerability type: CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

Affected software, patched versions and attribution

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 8.6.6. This is due to insufficient validation on the redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-8.6.6

Patched versions: 8.6.7

Researcher credit: daroo

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
December 15, 2025
CVSS
5.8
MediumCVE-2025-12174

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.5.2 - Missing Authorization to Authenticated (Subscriber+) Data Export and Slug Update

Affected versions: *-8.5.2

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'directorist_prepare_listings_export_file' and 'directorist_type_slug_change' AJAX actions in all versions up to, and including, 8.5.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export listing details and change the directorist slug.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-8.5.2

Patched versions: 8.5.3

Researcher credit: Rafshanzani Suhada

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
November 18, 2025
CVSS
6.5
HighCVE-2025-10488

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.4.8 - Authenticated (Subscriber+) Arbitrary File Move

Affected versions: *-8.4.8

Vulnerability type: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Affected software, patched versions and attribution

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to arbitrary file move due to insufficient file path validation in the add_listing_action AJAX action in all versions up to, and including, 8.4.8. This makes it possible for unauthenticated attackers to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php).

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-8.4.8

Patched versions: 8.4.9

Researcher credit: Arkadiusz Hydzik

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
October 24, 2025
CVSS
8.1
MediumCVE-2025-2224

Directorist <= 8.2 - Missing Authorization to Unauthenticated Arbitrary Post Publishing

Affected versions: *-8.2

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'parse_query' function in all versions up to, and including, 8.2. This makes it possible for unauthenticated attackers to update the post_status of any post to 'publish'.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-8.2

Patched versions: 8.3

Researcher credit: mikemyers

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
March 24, 2025
CVSS
5.3
HighCVE-2025-1570

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.1 - Privilege Escalation and Account Takeover via Weak OTP

Affected versions: *-8.1

Vulnerability type: CWE-640 Weak Password Recovery Mechanism for Forgotten Password

Affected software, patched versions and attribution

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 8.1. This is due to the directorist_generate_password_reset_pin_code() and reset_user_password() functions not having enough controls to prevent a successful brute force attack of the OTP to change a password, or verify that a password reset request came from an authorized user. This makes it possible for unauthenticated attackers to generate and brute force an OTP that makes it possible to change any users passwords, including an administrator.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-8.1

Patched versions: 8.2

Researcher credit: wesley (wcraft)

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
February 27, 2025
CVSS
8.1
MediumCVE-2024-12041

Directorist – AI-Powered WordPress Business Directory Plugin with Classified Ads Listings <= 8.0.12 - Unauthenticated User Information Exposure

Affected versions: *-8.0.12

Vulnerability type: CWE-359 Exposure of Private Personal Information to an Unauthorized Actor

Affected software, patched versions and attribution

The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including including usernames, email addresses, names, and more information about users.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-8.0.12

Patched versions: 8.1

Researcher credit: shaman0x01

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
January 31, 2025
CVSS
5.3
MediumCVE-2024-33929

Directorist <= 7.8.6 - Missing Authorization

Affected versions: *-7.8.6

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.8.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.8.6

Patched versions: 7.9.0

Researcher credit: Dhabaleshwar Das

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
April 29, 2024
CVSS
5.3
MediumCVE-2024-1322

Directorist <= 7.8.4 - Missing Authorization to Unauthenticated Settings Change

Affected versions: *-7.8.4

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 7.8.4. This makes it possible for unauthenticated attackers to recreate default pages and enable or disable monetization and change map provider.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.8.4

Patched versions: 7.8.5

Researcher credit: Lucio Sá

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
February 12, 2024
CVSS
5.3
LowCVE-2023-41798

Directorist <= 7.7.1 - CSV Injection

Affected versions: *-7.7.1

Vulnerability type: CWE-1236 Improper Neutralization of Formula Elements in a CSV File

Affected software, patched versions and attribution

The Directorist plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 7.7.1. This allows editor-level and above attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.7.1

Patched versions: 7.7.2

Researcher credit: Rafshanzani Suhada

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
September 5, 2023
CVSS
3.8
HighCVE-2023-1888

Directorist <= 7.5.4 - Authenticated (Subscriber+) Arbitrary User Password Reset to Privilege Escalation

Affected versions: *-7.5.4

Vulnerability type: CWE-20 Improper Input Validation

Affected software, patched versions and attribution

The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack of validation checks within login.php. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset the password of an arbitrary user and gain elevated (e.g., administrator) privileges.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.5.4

Patched versions: 7.5.5

Researcher credit: Alex Thomas

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
June 1, 2023
CVSS
8.8
MediumCVE-2023-1889

Directorist <= 7.5.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Post Deletion in listing_task

Affected versions: *-7.5.4

Vulnerability type: CWE-639 Authorization Bypass Through User-Controlled Key

Affected software, patched versions and attribution

The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to improper validation and authorization checks within the listing_task function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete arbitrary posts. Please note CVE-2023-35052 appears to be a duplicate of this issue.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.5.4

Patched versions: 7.5.5

Researcher credit: Alex Thomas

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
June 1, 2023
CVSS
6.5
HighCVE-2023-2252

Directorist <= 7.5.3 - Authenticated (Administrator+) Local File Inclusion

Affected versions: *-7.5.3

Vulnerability type: CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Affected software, patched versions and attribution

The Directorist for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.5.3 via the file parameter during CSV import. This allows administrator-level attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.5.3

Patched versions: 7.5.4

Researcher credit: rSolutions Security Team

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
May 10, 2023
CVSS
7.2
Medium

Appsero <= 1.2.1 - Missing Authorization

PT Addons for Elementor Lite: Currently marked unpatchedSubscribe2 – Form, Email Subscribers & Newsletters: Currently marked unpatchedwePOS – Point Of Sale (POS) for WooCommerce & Dokan: Currently marked unpatchedEasy Video Reviews – Testimonial Grid & Social Proof: Currently marked unpatchedWorth The Read: Currently marked unpatchedWoostify Sites Library: Currently marked unpatchedFlexTable – Data Table Sync with Google Sheets: Currently marked unpatchedPost Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget: Currently marked unpatchedWPEPP – Essential Security, Password Protect & Login Page Customizer: Currently marked unpatchedProduct Carousel Slider & Grid Ultimate for WooCommerce: Currently marked unpatchedProduct Gallery Slider, Additional Variation Images for WooCommerce: Currently marked unpatchedMarkdown Editor (Formerly Dark Mode): Currently marked unpatchedProject Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker: Currently marked unpatchedDashboard Welcome for Elementor: Currently marked unpatchedWP Dark Mode – Improve Accessibility with AI Powered Dark Theme: Currently marked unpatchedFuse Social Floating Sidebar: Currently marked unpatchedStylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator: Currently marked unpatchedSlider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider: Currently marked unpatchedProduct Category Slider for WooCommerce: Currently marked unpatchedFlexMeeting – Webinar & Meeting Plugin for Jitsi Meet: Currently marked unpatchedW4 Post List: Currently marked unpatchedweMail – Email Marketing, Newsletters Builder & Email Automations for WooCommerce: Currently marked unpatchedBuddyPress Builder for Elementor – BuddyBuilder: Currently marked unpatchedLegal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator: Currently marked unpatchedHappy Addons for Elementor: Currently marked unpatchedWP VR – 360 Panorama and Virtual Tour Builder: Currently marked unpatchedConversion Tracking for WooCommerce: Currently marked unpatchedSolid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews: Currently marked unpatchedEasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time: Currently marked unpatchedweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot: Currently marked unpatchedBangladeshi Payment Gateways – Make Payment Using QR Code: Currently marked unpatchedTexty – SMS Notification for WordPress, WooCommerce, Dokan and more: Currently marked unpatchedVisibility Logic for Elementor: Currently marked unpatchedPDF Invoices & Packing Slips for WooCommerce – Challan: Currently marked unpatchedDarklup – Enhanced WordPress Dark Mode, Dark Theme, Night Mode & Accessibility Plugin: Currently marked unpatchedExclusive Team for Elementor: Currently marked unpatchedClick to top: Currently marked unpatchedUpdate Image Tag Alt Attribute: Currently marked unpatchedMagical Posts Display – Elementor Advanced Posts widgets: Currently marked unpatchedGS Pinterest Portfolio – Pins Grid, Masonry, User Profile, Popup & Board Widgets: Currently marked unpatchedWP Mail Logging: Currently marked unpatchedDirectorist: AI-Powered Business Directory, Listings & Classified Ads: Currently marked unpatchedUser Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration: Currently marked unpatchedExclusive Addons for Elementor: Currently marked unpatchedBoostify Header Footer Builder for Elementor: Currently marked unpatchedStax Addons for Elementor: Currently marked unpatchedWP CTA – Call Now Button, Sticky Button & Call to Action Builder: Currently marked unpatchedGallery Box: Currently marked unpatchedPrime Elementor Addons – Lightweight Elementor Widgets for Faster Pages: Currently marked unpatchedWiremo – Product Reviews for WooCommerce: Currently marked unpatchedCart Lift – Abandoned Cart Recovery for WooCommerce and EDD: Currently marked unpatchedWPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell: Currently marked unpatchedProduct Category Showcase for WooCommerce: Currently marked unpatched

Affected versions: *-2.2; *-10.37; *-1.2.5; *-1.4.2; *-1.14; *-1.4.3; *-2.12.14; *-1.6.3

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function intended for administrator use.

PT Addons for Elementor Lite

Affected versions: *-2.2

Patched versions: Not supplied

Subscribe2 – Form, Email Subscribers & Newsletters

Affected versions: *-10.37

Patched versions: 10.38

wePOS – Point Of Sale (POS) for WooCommerce & Dokan

Affected versions: *-1.2.5

Patched versions: 1.2.6

Easy Video Reviews – Testimonial Grid & Social Proof

Affected versions: *-1.4.2

Patched versions: 1.5.0

Worth The Read

Affected versions: *-1.14

Patched versions: 1.14.1

Woostify Sites Library

Affected versions: *-1.4.3

Patched versions: 1.4.4

FlexTable – Data Table Sync with Google Sheets

Affected versions: *-2.12.14

Patched versions: 2.12.15

Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

Affected versions: *-1.6.3

Patched versions: 1.6.4

WPEPP – Essential Security, Password Protect & Login Page Customizer

Affected versions: *-1.2.3

Patched versions: 1.2.4

Product Carousel Slider & Grid Ultimate for WooCommerce

Affected versions: *-1.9.3

Patched versions: 1.9.4

Product Gallery Slider, Additional Variation Images for WooCommerce

Affected versions: *-2.2.6

Patched versions: 2.2.7

Markdown Editor (Formerly Dark Mode)

Affected versions: *-4.1.2

Patched versions: 4.1.3

Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

Affected versions: *-2.6.12

Patched versions: 2.6.13

Dashboard Welcome for Elementor

Affected versions: *-1.0.6

Patched versions: 1.0.7

WP Dark Mode – Improve Accessibility with AI Powered Dark Theme

Affected versions: *-3.0.4

Patched versions: 3.0.5

Fuse Social Floating Sidebar

Affected versions: *-5.4.6

Patched versions: 5.4.7

Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator

Affected versions: *-7.3.6

Patched versions: 7.3.7

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Affected versions: *-3.28.0

Patched versions: 3.28.1

Product Category Slider for WooCommerce

Affected versions: *-4.1.5

Patched versions: 4.1.6

FlexMeeting – Webinar & Meeting Plugin for Jitsi Meet

Affected versions: *-1.2.5

Patched versions: 2.0.0

W4 Post List

Affected versions: *-2.4.2

Patched versions: 2.4.3

weMail – Email Marketing, Newsletters Builder & Email Automations for WooCommerce

Affected versions: *-1.14.1

Patched versions: 1.14.2

BuddyPress Builder for Elementor – BuddyBuilder

Affected versions: *-1.7.1

Patched versions: 1.7.2

Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator

Affected versions: *-1.4.1

Patched versions: 1.4.2

Happy Addons for Elementor

Affected versions: *-3.8.2

Patched versions: 3.8.3

WP VR – 360 Panorama and Virtual Tour Builder

Affected versions: *-8.2.5

Patched versions: 8.2.6

Conversion Tracking for WooCommerce

Affected versions: *-2.0.10

Patched versions: 2.0.11

Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews

Affected versions: *-1.9.7

Patched versions: 1.9.8

EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time

Affected versions: *-1.0.9

Patched versions: 1.1.0

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

Affected versions: 1.6-1.7.5

Patched versions: 1.7.6

Bangladeshi Payment Gateways – Make Payment Using QR Code

Affected versions: *-2.0.6

Patched versions: 2.0.7

Texty – SMS Notification for WordPress, WooCommerce, Dokan and more

Affected versions: *-1.1.1

Patched versions: 1.1.2

Visibility Logic for Elementor

Affected versions: *-2.3.3

Patched versions: 2.3.4

PDF Invoices & Packing Slips for WooCommerce – Challan

Affected versions: *-3.4.8

Patched versions: 3.4.9

Darklup – Enhanced WordPress Dark Mode, Dark Theme, Night Mode & Accessibility Plugin

Affected versions: *-2.1.1

Patched versions: 2.1.2

Exclusive Team for Elementor

Affected versions: *-1.2.4

Patched versions: Not supplied

Click to top

Affected versions: *-1.2.19

Patched versions: 1.2.20

Update Image Tag Alt Attribute

Affected versions: *-2.4.3

Patched versions: Not supplied

Magical Posts Display – Elementor Advanced Posts widgets

Affected versions: *-1.2.15

Patched versions: 1.2.16

GS Pinterest Portfolio – Pins Grid, Masonry, User Profile, Popup & Board Widgets

Affected versions: *-1.6.2

Patched versions: 1.6.3

WP Mail Logging

Affected versions: 1.10.5

Patched versions: 1.11.0

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.7.1

Patched versions: 7.7.2

User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration

Affected versions: *-3.6.0

Patched versions: 3.6.1

Exclusive Addons for Elementor

Affected versions: *-2.6.1

Patched versions: 2.6.2

Boostify Header Footer Builder for Elementor

Affected versions: *-1.2.8

Patched versions: 1.2.9

Stax Addons for Elementor

Affected versions: *-1.4.3

Patched versions: 1.4.4

WP CTA – Call Now Button, Sticky Button & Call to Action Builder

Affected versions: *-1.5.8

Patched versions: 1.5.9

Gallery Box

Affected versions: *-1.7.30

Patched versions: 1.7.31

Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages

Affected versions: *-1.0.1

Patched versions: 1.0.2

Wiremo – Product Reviews for WooCommerce

Affected versions: *-1.4.96

Patched versions: 1.4.97

Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD

Affected versions: *-3.1.3

Patched versions: 3.1.4

WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

Affected versions: *-2.6.4

Patched versions: 2.6.5

Product Category Showcase for WooCommerce

Affected versions: *-1.1.9

Patched versions: 2.0.0

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
December 16, 2022
CVSS
4.3
MediumCVE-2022-47150

Appsero <= 1.2.0 - Cross-Site Request Forgery

PT Addons for Elementor Lite: Currently marked unpatchedSubscribe2 – Form, Email Subscribers & Newsletters: Currently marked unpatchedwePOS – Point Of Sale (POS) for WooCommerce & Dokan: Currently marked unpatchedEasy Video Reviews – Testimonial Grid & Social Proof: Currently marked unpatchedWorth The Read: Currently marked unpatchedWoostify Sites Library: Currently marked unpatchedFlexTable – Data Table Sync with Google Sheets: Currently marked unpatchedPost Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget: Currently marked unpatchedWPEPP – Essential Security, Password Protect & Login Page Customizer: Currently marked unpatchedProduct Carousel Slider & Grid Ultimate for WooCommerce: Currently marked unpatchedProduct Gallery Slider, Additional Variation Images for WooCommerce: Currently marked unpatchedMarkdown Editor (Formerly Dark Mode): Currently marked unpatchedProject Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker: Currently marked unpatchedDashboard Welcome for Elementor: Currently marked unpatchedWP Dark Mode – Improve Accessibility with AI Powered Dark Theme: Currently marked unpatchedFuse Social Floating Sidebar: Currently marked unpatchedStylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator: Currently marked unpatchedSlider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider: Currently marked unpatchedProduct Category Slider for WooCommerce: Currently marked unpatchedFlexMeeting – Webinar & Meeting Plugin for Jitsi Meet: Currently marked unpatchedW4 Post List: Currently marked unpatchedweMail – Email Marketing, Newsletters Builder & Email Automations for WooCommerce: Currently marked unpatchedBuddyPress Builder for Elementor – BuddyBuilder: Currently marked unpatchedLegal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator: Currently marked unpatchedHappy Addons for Elementor: Currently marked unpatchedWP VR – 360 Panorama and Virtual Tour Builder: Currently marked unpatchedConversion Tracking for WooCommerce: Currently marked unpatchedSolid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews: Currently marked unpatchedEasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time: Currently marked unpatchedweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot: Currently marked unpatchedBangladeshi Payment Gateways – Make Payment Using QR Code: Currently marked unpatchedTexty – SMS Notification for WordPress, WooCommerce, Dokan and more: Currently marked unpatchedVisibility Logic for Elementor: Currently marked unpatchedPDF Invoices & Packing Slips for WooCommerce – Challan: Currently marked unpatchedDarklup – Enhanced WordPress Dark Mode, Dark Theme, Night Mode & Accessibility Plugin: Currently marked unpatchedExclusive Team for Elementor: Currently marked unpatchedClick to top: Currently marked unpatchedUpdate Image Tag Alt Attribute: Currently marked unpatchedMagical Posts Display – Elementor Advanced Posts widgets: Currently marked unpatchedGS Pinterest Portfolio – Pins Grid, Masonry, User Profile, Popup & Board Widgets: Currently marked unpatchedWP Mail Logging: Currently marked unpatchedDirectorist: AI-Powered Business Directory, Listings & Classified Ads: Currently marked unpatchedUser Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration: Currently marked unpatchedZero BS Accounting: Currently marked unpatchedExclusive Addons for Elementor: Currently marked unpatchedBoostify Header Footer Builder for Elementor: Currently marked unpatchedStax Addons for Elementor: Currently marked unpatchedWP CTA – Call Now Button, Sticky Button & Call to Action Builder: Currently marked unpatchedGallery Box: Currently marked unpatchedPrime Elementor Addons – Lightweight Elementor Widgets for Faster Pages: Currently marked unpatchedWiremo – Product Reviews for WooCommerce: Currently marked unpatchedCart Lift – Abandoned Cart Recovery for WooCommerce and EDD: Currently marked unpatchedWPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell: Currently marked unpatchedProduct Category Showcase for WooCommerce: Currently marked unpatched

Affected versions: *-2.2; *-10.37; *-1.2.5; *-1.4.2; *-1.14; *-1.4.3; *-2.12.14; *-1.6.3

Vulnerability type: CWE-352 Cross-Site Request Forgery (CSRF)

Affected software, patched versions and attribution

The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function intended for administrator use via forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

PT Addons for Elementor Lite

Affected versions: *-2.2

Patched versions: Not supplied

Subscribe2 – Form, Email Subscribers & Newsletters

Affected versions: *-10.37

Patched versions: 10.38

wePOS – Point Of Sale (POS) for WooCommerce & Dokan

Affected versions: *-1.2.5

Patched versions: 1.2.6

Easy Video Reviews – Testimonial Grid & Social Proof

Affected versions: *-1.4.2

Patched versions: 1.5.0

Worth The Read

Affected versions: *-1.14

Patched versions: 1.14.1

Woostify Sites Library

Affected versions: *-1.4.3

Patched versions: 1.4.4

FlexTable – Data Table Sync with Google Sheets

Affected versions: *-2.12.14

Patched versions: 2.12.15

Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

Affected versions: *-1.6.3

Patched versions: 1.6.4

WPEPP – Essential Security, Password Protect & Login Page Customizer

Affected versions: *-1.2.3

Patched versions: 1.2.4

Product Carousel Slider & Grid Ultimate for WooCommerce

Affected versions: *-1.9.3

Patched versions: 1.9.4

Product Gallery Slider, Additional Variation Images for WooCommerce

Affected versions: *-2.2.6

Patched versions: 2.2.7

Markdown Editor (Formerly Dark Mode)

Affected versions: *-4.1.2

Patched versions: 4.1.3

Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

Affected versions: *-2.6.12

Patched versions: 2.6.13

Dashboard Welcome for Elementor

Affected versions: *-1.0.6

Patched versions: 1.0.7

WP Dark Mode – Improve Accessibility with AI Powered Dark Theme

Affected versions: *-3.0.4

Patched versions: 3.0.5

Fuse Social Floating Sidebar

Affected versions: *-5.4.6

Patched versions: 5.4.7

Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator

Affected versions: *-7.3.6

Patched versions: 7.3.7

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Affected versions: *-3.28.0

Patched versions: 3.28.1

Product Category Slider for WooCommerce

Affected versions: *-4.1.5

Patched versions: 4.1.6

FlexMeeting – Webinar & Meeting Plugin for Jitsi Meet

Affected versions: *-1.2.5

Patched versions: 2.0.0

W4 Post List

Affected versions: *-2.4.2

Patched versions: 2.4.3

weMail – Email Marketing, Newsletters Builder & Email Automations for WooCommerce

Affected versions: *-1.14.1

Patched versions: 1.14.2

BuddyPress Builder for Elementor – BuddyBuilder

Affected versions: *-1.7.1

Patched versions: 1.7.2

Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator

Affected versions: *-1.4.1

Patched versions: 1.4.2

Happy Addons for Elementor

Affected versions: *-3.8.2

Patched versions: 3.8.3

WP VR – 360 Panorama and Virtual Tour Builder

Affected versions: *-8.2.5

Patched versions: 8.2.6

Conversion Tracking for WooCommerce

Affected versions: *-2.0.10

Patched versions: 2.0.11

Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews

Affected versions: *-1.9.7

Patched versions: 1.9.8

EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time

Affected versions: *-1.0.9

Patched versions: 1.1.0

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

Affected versions: 1.6-1.7.5

Patched versions: 1.7.6

Bangladeshi Payment Gateways – Make Payment Using QR Code

Affected versions: *-2.0.6

Patched versions: 2.0.7

Texty – SMS Notification for WordPress, WooCommerce, Dokan and more

Affected versions: *-1.1.1

Patched versions: 1.1.2

Visibility Logic for Elementor

Affected versions: *-2.3.3

Patched versions: 2.3.4

PDF Invoices & Packing Slips for WooCommerce – Challan

Affected versions: *-3.4.8

Patched versions: 3.4.9

Darklup – Enhanced WordPress Dark Mode, Dark Theme, Night Mode & Accessibility Plugin

Affected versions: *-2.1.1

Patched versions: 2.1.2

Exclusive Team for Elementor

Affected versions: *-1.2.4

Patched versions: Not supplied

Click to top

Affected versions: *-1.2.19

Patched versions: 1.2.20

Update Image Tag Alt Attribute

Affected versions: *-2.4.3

Patched versions: Not supplied

Magical Posts Display – Elementor Advanced Posts widgets

Affected versions: *-1.2.15

Patched versions: 1.2.16

GS Pinterest Portfolio – Pins Grid, Masonry, User Profile, Popup & Board Widgets

Affected versions: *-1.6.2

Patched versions: 1.6.3

WP Mail Logging

Affected versions: *-1.10.5

Patched versions: 1.11.0

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.7.1

Patched versions: 7.7.2

User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration

Affected versions: *-3.6.0

Patched versions: 3.6.1

Zero BS Accounting

Affected versions: *-1.0.6

Patched versions: 2.0.0

Exclusive Addons for Elementor

Affected versions: *-2.6.1

Patched versions: 2.6.2

Boostify Header Footer Builder for Elementor

Affected versions: *-1.2.8

Patched versions: 1.2.9

Stax Addons for Elementor

Affected versions: *-1.4.3

Patched versions: 1.4.4

WP CTA – Call Now Button, Sticky Button & Call to Action Builder

Affected versions: *-1.5.8

Patched versions: 1.5.9

Gallery Box

Affected versions: *-1.7.30

Patched versions: 1.7.31

Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages

Affected versions: *-1.0.1

Patched versions: 1.0.2

Wiremo – Product Reviews for WooCommerce

Affected versions: *-1.4.96

Patched versions: 1.4.97

Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD

Affected versions: *-3.1.3

Patched versions: 3.1.4

WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

Affected versions: 2.6.4

Patched versions: 2.6.5

Product Category Showcase for WooCommerce

Affected versions: *-1.1.9

Patched versions: 2.0.0

Researcher credit: István Márton

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
December 14, 2022
CVSS
4.3
MediumCVE-2022-3961

Directorist <= 7.4.3 - Authenticated (Subscriber+) Sensitive Information Disclosure

Affected versions: *-7.4.3

Vulnerability type: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Affected software, patched versions and attribution

The Directorist for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 7.4.3. This can allow authenticated attackers, with subscriber-level permissions or higher, to extract sensitive system data.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.4.3

Patched versions: 7.4.4

Researcher credit: István Márton

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
November 28, 2022
CVSS
4.3
HighCVE-2022-3930

Directorist <= 7.4.2.1 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Change

Affected versions: *-7.4.2.1

Vulnerability type: CWE-639 Authorization Bypass Through User-Controlled Key

Affected software, patched versions and attribution

The Directorist plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 7.4.2.1. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for subscriber-level attackers to change user passwords and potentially take over administrator accounts.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.4.2.1

Patched versions: 7.4.2.2

Researcher credit: cydave

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
November 21, 2022
CVSS
8.8
HighCVE-2022-2376

Directorist <= 7.3.0 - Sensitive Information Disclosure

Affected versions: *-7.3.0

Vulnerability type: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Affected software, patched versions and attribution

The plugin Directorist for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 7.3.0. This could allow unauthenticated attackers to extract sensitive user data such as emails.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.3.0

Patched versions: 7.3.1

Researcher credit: Krzysztof Zając

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
August 10, 2022
CVSS
7.5
MediumCVE-2022-2377

Directorist – WordPress Business Directory Plugin with Classified Ads Listings <= 7.2.3 - Missing Authorization

Affected versions: *-7.2.3

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the send_announcement() function in versions up to, and including, 7.2.3. This makes it possible for authenticated attackers with subscriber level permissions to send arbitrary emails from the vulnerable WordPress site.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.2.3

Patched versions: 7.3.0

Researcher credit: Krzysztof Zając

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
July 26, 2022
CVSS
6.3
HighCVE-2022-2046

Directorist <= 7.2.2 - Authenticated (Admin+) Arbitrary File Upload

Affected versions: *-7.2.2

Vulnerability type: CWE-434 Unrestricted Upload of File with Dangerous Type

Affected software, patched versions and attribution

The Directorist plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the atbdp_download_file() AJAX action in versions up to, and including, 7.2.2. This makes it possible for authenticated attackers with administrative privileges to upload arbitrary files on the affected sites server which may make remote code execution possible. This only affects sites where administrator have been restricted in their uploading files capabilities.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.2.2

Patched versions: 7.2.3

Researcher credit: Rafie Muhammad

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
July 18, 2022
CVSS
7.2
HighCVE-2021-24981

Directorist <= 7.0.6.1 - Cross-Site Request Forgery to Arbitrary File Upload

Affected versions: *-7.0.6.1

Vulnerability type: CWE-352 Cross-Site Request Forgery (CSRF)

Affected software, patched versions and attribution

The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.0.6.1

Patched versions: 7.0.6.2

Researcher credit: lostbytes1

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
November 16, 2021
CVSS
8.8

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

Production Feed records are aggregated without claiming discovery, exploitation or infection. Applicable source notices remain attached to individual records. Read the methodology.