The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to arbitrary file move due to insufficient file path validation in the add_listing_action AJAX action in all versions up to, and including, 8.4.8. This makes it possible for unauthenticated attackers to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php).
Metrics
Affected Vendors & Products
References
History
Mon, 27 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpwax Wpwax directorist |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpwax Wpwax directorist |
Mon, 27 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 25 Oct 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to arbitrary file move due to insufficient file path validation in the add_listing_action AJAX action in all versions up to, and including, 8.4.8. This makes it possible for unauthenticated attackers to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php). | |
| Title | Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.4.8 - Authenticated (Subscriber+) Arbitrary File Move | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-10-25T06:49:21.186Z
Updated: 2025-10-27T15:54:15.168Z
Reserved: 2025-09-15T14:42:08.792Z
Link: CVE-2025-10488
Updated: 2025-10-27T15:54:09.339Z
Status : Awaiting Analysis
Published: 2025-10-25T07:15:37.323
Modified: 2025-10-27T13:20:15.637
Link: CVE-2025-10488
No data.