← back
CVE-2023-2252low

Directorist < 7.5.4 - Admin+ LFI

23Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 2.7epss 1.3%
exploitation probability
1.3%top 31% of all CVEs
observed exploitation
nono source reports it
The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Affected products
Unknown · Directorist