PT-2025-43716 · WordPress · Directorist

Arkadiusz Hydzik

·

Published

2025-10-25

·

Updated

2025-10-30

·

CVE-2025-10488

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Directorist versions up to and including 8.4.8
Description The Directorist plugin for WordPress is susceptible to arbitrary file move due to inadequate file path validation within the add listing action AJAX action. This allows unauthenticated attackers to move arbitrary files on the server. Successful exploitation, such as moving files like wp-config.php, can lead to remote code execution.
Recommendations Update to version 8.4.9 or later.

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-10488

Affected Products

Directorist