Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2024-12041
Disclosure Date: February 01, 2025 (last updated February 01, 2025)
The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including including usernames, email addresses, names, and more information about users.
0
Attacker Value
Unknown
CVE-2023-35052
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in wpWax - WP Business Directory Plugin and Classified Listings Directory Directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through 7.5.4.
0
Attacker Value
Unknown
CVE-2024-33929
Disclosure Date: May 03, 2024 (last updated May 03, 2024)
Missing Authorization vulnerability in wpWax Directorist.This issue affects Directorist: from n/a through 7.8.6.
0
Attacker Value
Unknown
CVE-2024-1322
Disclosure Date: February 29, 2024 (last updated February 29, 2024)
The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 7.8.4. This makes it possible for unauthenticated attackers to recreate default pages and enable or disable monetization and change map provider.
0
Attacker Value
Unknown
CVE-2023-2252
Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.
0
Attacker Value
Unknown
CVE-2023-41798
Disclosure Date: November 07, 2023 (last updated November 15, 2023)
Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Directory Plugin with Classified Ads Listing.This issue affects Directorist – WordPress Business Directory Plugin with Classified Ads Listings: from n/a through 7.7.1.
0
Attacker Value
Unknown
CVE-2023-1889
Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to improper validation and authorization checks within the listing_task function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete arbitrary posts.
0
Attacker Value
Unknown
CVE-2023-1888
Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack of validation checks within login.php. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset the password of an arbitrary user and gain elevated (e.g., administrator) privileges.
0
Attacker Value
Unknown
CVE-2022-3961
Disclosure Date: December 19, 2022 (last updated October 08, 2023)
The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessing sensitive system information.
0
Attacker Value
Unknown
CVE-2022-3930
Disclosure Date: December 12, 2022 (last updated November 08, 2023)
The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.
0