VulnerabilityModified
CVE-2023-2252
The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.
LOW 2.7EPSS 1.34%
Does this matter?
Lower severity and a low EPSS score (1.34%). Track it; it rarely justifies an emergency change on its own.
Description
The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.
- CVSS 3.1
- 2.7 LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.34% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- wpwax/directorist
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/9da6eede-10d0-4609-8b97-4a5d38fa8e69/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/9da6eede-10d0-4609-8b97-4a5d38fa8e69/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.