Junglewise Threat Intelligence

CVE-2026-77757: Directorist arbitrary image move via path traversal

CVE-2026-77757 · Severity: medium · CVSS 5.4 · Published 2026-08-26

Technologies: Directorist. Vendors: Directorist.

Executive brief

The Directorist WordPress plugin is a business directory and classified ads tool used by website owners to manage listings. A vulnerability allows subscriber-level users to move arbitrary image files from anywhere on the server into a public directory, exposing sensitive files and potentially deleting originals from restricted locations.

Technical details

The plugin fails to sanitize user-supplied image file paths in the REST API listing submission endpoint before using them in file move operations. An attacker with subscriber privileges can craft a path traversal payload (e.g., `../../../../../../../tmp/victim.png`) via the REST v2 listings endpoint to relocate server-readable files outside the intended uploads directory into a public uploads folder. The vulnerability requires subscriber account access and a pre-existing image file to stage, but results in arbitrary file disclosure and deletion. The plugin validates that only images are moved and prevents overwriting, but these controls do not address path traversal. Fixed in version 8.9.3.

Affected products

  • Directorist Directorist 8.5 through 8.9.2

Timeline

  • 2026-08-24: disclosed
  • 2026-08-26: patched: Fixed in version 8.9.3

References