nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-2252 CVE-2023-2252
LOWNuclei
Directorist < 7.5.4 - Admin+ LFI
Record summary
CVE-2023-2252 has a selected CVSS score of 2.7 (low); EIP currently links 1 Nuclei template.
Description
The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 8, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
DirectoristDefault status: unaffected | CVE List | Before 7.5.4 | affected |
Nuclei templates
1ProjectDiscoveryLOWDirectorist < 7.5.4 - Local File InclusionCVSS 2.7
Directorist before 7.5.4 is susceptible to Local File Inclusion as it does not validate the file parameter when importing CSV files.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the entire system.
Remediation
Fixed in version 7.5.4
WeaknessesCWE-22
Authorsr3Y3r53
Template tagscve2023cvewpscanlfidirectoristwordpresswp-pluginwpauthenticatedwpwaxvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:wpwax:directorist:*:*:*:*:*:wordpress:*:*
https://wpscan.com/vulnerability/9da6eede-10d0-4609-8b97-4a5d38fa8e69 https://wordpress.org/plugins/directorist/advanced/ https://nvd.nist.gov/vuln/detail/CVE-2023-2252
Source: ProjectDiscovery
References
2wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/9da6eede-10d0-4609-8b97-4a5d38fa8e69