CVE-2025-64250: WordPress Directorist plugin <= 8.6.6 - Open Redirection vulnerability
Published Dec 16, 2025
·Updated
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wpWax Directorist directorist allows Phishing.This issue affects Directorist: from n/a through <= 8.6.6.
Affected Software
1 affected component
wpWax Directorist<=8.6.6
Event History
Dec 16, 2025
CVE Published
via MITRE·08:12 AM
Data Sourced
via MITRE·08:12 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Sep 6, 58290
Event
via MITRE·11:43 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-64250?
CVE-2025-64250 has been rated as a medium severity vulnerability due to its potential to facilitate phishing attacks.
2
How do I fix CVE-2025-64250?
To mitigate CVE-2025-64250, it is recommended to update the Directorist plugin to the latest version beyond 8.5.6.
3
What types of attacks can CVE-2025-64250 lead to?
CVE-2025-64250 can lead to open redirect attacks, which may be exploited for phishing purposes.
4
Which versions of Directorist are affected by CVE-2025-64250?
CVE-2025-64250 affects Directorist plugin versions up to and including 8.5.6.
5
Is there a known exploit for CVE-2025-64250?
Currently, there are no widely reported exploits for CVE-2025-64250, but it poses a significant risk if left unpatched.