Directorist
Vendor:
First CVE: Dec 21, 2021 · Active for 4 years
18
Total CVEs
More Total CVEs than 94% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Directorist over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 21, 2021
4 years ago
Most Recent CVE
Jul 13, 2026
15 days ago
CVE Severity & Scoring
Directorist18 CVEs
61%
22%
11%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (94.4%)
High1 (5.6%)
Unknown0 (0.0%)
User Interaction
None16 (88.9%)
Unknown0 (0.0%)
Required2 (11.1%)
Privileges Required
Low7 (38.9%)
High2 (11.1%)
None9 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-59518CRITICAL Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2. | Jul 13, 2026 | 9.8 | 41 | NO | NO |
CVE-2025-1570CRITICAL The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions u | Feb 28, 2025 | 9.8 | 28 | NO | NO |
CVE-2023-1888HIGH The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack of validation checks within lo | Jun 9, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-41798HIGH Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Directory Plugin with Classified Ads Listing.This issue affects Di | Nov 7, 2023 | 8.8 | 24 | NO | NO |
CVE-2021-24981HIGH The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins | Dec 21, 2021 | 7.5 | 24 | NO | NO |
CVE-2025-68069HIGH Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/ | Feb 20, 2026 | 7.1 | 23 | NO | NO |
CVE-2022-2376MEDIUM The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users | Sep 5, 2022 | 5.3 | 23 | NO | YES |
CVE-2022-3961MEDIUM The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessing sensitive system information. | Dec 19, 2022 | 6.5 | 22 | NO | NO |
CVE-2022-3930MEDIUM The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own. | Dec 12, 2022 | 6.5 | 22 | NO | NO |
CVE-2026-39509MEDIUM Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/ | Apr 8, 2026 | 5.3 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
11.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Directorist
Top CWEs
Versions
No cataloged versions.