---
id: CVE-2025-10488
title: >-
  The Directorist: AI-Powered Business Directory Plugin with Classified Ads
  Listings plugin for WordPress is vulnerable to arbitrary file move due to
  insufficient file path validation in the add_listing_action AJAX action in all
  versions u…
summary: >-
  The Directorist: AI-Powered Business Directory Plugin with Classified Ads
  Listings plugin for WordPress is vulnerable to arbitrary file move due to
  insufficient file path validation in the add_listing_action AJAX action in all
  versions u…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-22
published: '2025-10-25'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10488'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/directorist/tags/8.4.5/includes/classes/class-add-listing.php#L634
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3377181%40directorist&new=3377181%40directorist&sfp_email=&sfph_mail=
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/2249ef72-9955-4636-b32f-e88720923268?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00911
epssPercentile: 0.58755
ingestedAt: '2026-10-08T11:31:27.582Z'
---

## Overview

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to arbitrary file move due to insufficient file path validation in the add_listing_action AJAX action in all versions up to, and including, 8.4.8. This makes it possible for unauthenticated attackers to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
