CVE-2025-1570: Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.1 - Privilege Escalation and Account Takeover via Weak OTP
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 8.1. This is due to the directoristgeneratepasswordresetpincode() and resetuserpassword() functions not having enough controls to prevent a successful brute force attack of the OTP to change a password, or verify that a password reset request came from an authorized user. This makes it possible for unauthenticated attackers to generate and brute force an OTP that makes it possible to change any users passwords, including an administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1570?
CVE-2025-1570 is classified as a privilege escalation vulnerability that can lead to account takeover.
How do I fix CVE-2025-1570?
To fix CVE-2025-1570, update the Directorist AI-Powered Business Directory Plugin to version 8.2 or later.
Who is affected by CVE-2025-1570?
All users of the Directorist AI-Powered Business Directory Plugin for WordPress prior to version 8.2 are affected by CVE-2025-1570.
What versions of the Directorist plugin are impacted by CVE-2025-1570?
CVE-2025-1570 affects all versions of the Directorist AI-Powered Business Directory Plugin up to and including version 8.1.
What impact does CVE-2025-1570 have?
CVE-2025-1570 allows for privilege escalation, potentially enabling attackers to take over user accounts.