Executive brief
Directorist is a popular WordPress plugin used to create business directories and classified listings. A critical security flaw allows an attacker to inject malicious data that the website then processes as code. This could lead to a complete takeover of the website, theft of customer data, or a total service outage.
Technical details
A PHP Object Injection vulnerability exists in the wpWax Directorist plugin for WordPress due to the insecure deserialization of user-supplied input. An unauthenticated remote attacker can exploit this by submitting specially crafted data to a vulnerable component. If a suitable Property-Oriented Programming (POP) chain is present on the server, the attacker can achieve remote code execution, perform SQL injection, or conduct arbitrary file manipulation. The vulnerability is present in versions up to 8.8.2 and has been addressed in version 8.8.3.
Affected products
- wpWax Directorist <= 8.8.2
Timeline
- 2026-06-30: other: Vulnerability reported by researcher dutafi
- 2026-07-09: advisory: Patchstack published advisory
- 2026-07-13: disclosed: CVE published to NVD
- 2026-07-13: patched: Version 8.8.3 released to address the issue