Record summary

CVE-2023-2252 has a selected CVSS score of 2.7 (low); EIP currently links 1 Nuclei template.

Description

The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 8, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Directorist

Default status: unaffected

CVE ListBefore 7.5.4affected

Nuclei templates

1
ProjectDiscoveryLOWDirectorist < 7.5.4 - Local File InclusionCVSS 2.7

Directorist before 7.5.4 is susceptible to Local File Inclusion as it does not validate the file parameter when importing CSV files.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the entire system.

Remediation

Fixed in version 7.5.4

WeaknessesCWE-22
Authorsr3Y3r53
Template tagscve2023cvewpscanlfidirectoristwordpresswp-pluginwpauthenticatedwpwaxvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:wpwax:directorist:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2