PT-2025-1733 · WordPress · The Directorist: Ai-Powered Wordpress Business Directory Plugin With Classified Ads Listings
Khayal Farzaliyev
+1
·
Published
2025-02-01
·
Updated
2025-03-02
·
CVE-2024-12041
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress versions up to, and including, 8.0.12
Description
The issue allows unauthenticated attackers to extract sensitive data, including usernames, email addresses, names, and more information about users, via the "/wp-json/directorist/v1/users/" endpoint.
Recommendations
For versions up to, and including, 8.0.12, update to a version higher than 8.0.12 to resolve the issue.
As a temporary workaround, consider restricting access to the "/wp-json/directorist/v1/users/" endpoint until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Directorist: Ai-Powered Wordpress Business Directory Plugin With Classified Ads Listings