CVE-2023-2252: Wpwax Directorist
Low severity, CVSS 2.7. EPSS: 1.3% chance of exploitation in the next 30 days.
The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.
Affected products
- Wpwax Directorist: before 7.5.4 (fixed in 7.5.4)
Published 2024-01-16. Last modified 2026-06-17.