Directorist < 7.5.4 - Admin+ LFI
23Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 2.7epss 1.3%
exploitation probability
1.3%top 31% of all CVEs
observed exploitation
nono source reports it
The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Affected products
Unknown · Directorist