Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2024-12041

Disclosure Date: February 01, 2025 (last updated February 01, 2025)
The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including including usernames, email addresses, names, and more information about users.
Attacker Value
Unknown

CVE-2023-35052

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in wpWax - WP Business Directory Plugin and Classified Listings Directory Directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through 7.5.4.
0
Attacker Value
Unknown

CVE-2024-33929

Disclosure Date: May 03, 2024 (last updated May 03, 2024)
Missing Authorization vulnerability in wpWax Directorist.This issue affects Directorist: from n/a through 7.8.6.
0
Attacker Value
Unknown

CVE-2024-1322

Disclosure Date: February 29, 2024 (last updated February 29, 2024)
The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 7.8.4. This makes it possible for unauthenticated attackers to recreate default pages and enable or disable monetization and change map provider.
0
Attacker Value
Unknown

CVE-2023-2252

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.
Attacker Value
Unknown

CVE-2023-41798

Disclosure Date: November 07, 2023 (last updated November 15, 2023)
Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Directory Plugin with Classified Ads Listing.This issue affects Directorist – WordPress Business Directory Plugin with Classified Ads Listings: from n/a through 7.7.1.
Attacker Value
Unknown

CVE-2023-1889

Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to improper validation and authorization checks within the listing_task function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete arbitrary posts.
Attacker Value
Unknown

CVE-2023-1888

Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack of validation checks within login.php. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset the password of an arbitrary user and gain elevated (e.g., administrator) privileges.
Attacker Value
Unknown

CVE-2022-3961

Disclosure Date: December 19, 2022 (last updated October 08, 2023)
The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessing sensitive system information.
Attacker Value
Unknown

CVE-2022-3930

Disclosure Date: December 12, 2022 (last updated November 08, 2023)
The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.