CVE-2025-12174: Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.5.2 - Missing Authorization to Authenticated (Subscriber+) Data Export and Slug Update
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'directoristpreparelistingsexportfile' and 'directoristtypeslugchange' AJAX actions in all versions up to, and including, 8.5.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export listing details and change the directorist slug.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12174?
CVE-2025-12174 has a medium severity rating due to the risk of unauthorized access.
How do I fix CVE-2025-12174?
To fix CVE-2025-12174, update the Directorist AI-Powered Business Directory Plugin to version 8.5.3 or later.
What specific actions are vulnerable in CVE-2025-12174?
CVE-2025-12174 is vulnerable due to missing capability checks in the 'directorist_prepare_listings_export_file' and 'directorist_type_slug_change' AJAX actions.
Can CVE-2025-12174 be exploited remotely?
Yes, CVE-2025-12174 can be exploited remotely, allowing unauthorized users to access sensitive functionality.
Who is affected by CVE-2025-12174?
CVE-2025-12174 affects all versions of the Directorist AI-Powered Business Directory Plugin up to and including version 8.5.2.