Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8049 | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'parse_query' function in all versions up to, and including, 8.2. This makes it possible for unauthenticated attackers to update the post_status of any post to 'publish'. |
Mon, 31 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Mar 2025 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'parse_query' function in all versions up to, and including, 8.2. This makes it possible for unauthenticated attackers to update the post_status of any post to 'publish'. | |
| Title | Directorist <= 8.2 - Missing Authorization to Unauthenticated Arbitrary Post Publishing | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:58:26.368Z
Reserved: 2025-03-11T17:29:40.677Z
Link: CVE-2025-2224
Updated: 2025-03-31T18:18:24.651Z
Status : Deferred
Published: 2025-03-25T06:15:41.327
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-2224
No data.
OpenCVE Enrichment
Updated: 2026-04-21T21:45:25Z
EUVD