Executive brief
The Directorist WordPress plugin, used to manage business directories and classified ads, contains a server-side request forgery (SSRF) vulnerability in its avatar URL handling. An attacker with a subscriber account or higher privilege can supply a malicious URL that forces the server to make requests to internal network addresses, potentially exposing sensitive internal services and data.
Technical details
The plugin fails to validate user-supplied URLs before fetching them server-side via the avatar URL field. Users with subscriber role and above can abuse this to perform SSRF attacks against internal addresses. An attacker gains the ability to probe internal network services, bypass firewall restrictions, and potentially read internal resources if accessible to the web server process.
Affected products
- directorist Directorist before 8.9.5
Timeline
- 2026-09-21: disclosed
- 2026-09-23: patched: Fixed in version 8.9.5