Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wpWax Directorist directorist allows Phishing.This issue affects Directorist: from n/a through <= 8.6.6.
Published: 2025-12-16
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Directorist plugin for WordPress contains a flaw that allows an attacker to redirect users to a site of the attacker’s choice. This open redirection leads to phishing attacks by convincing users that the link is legitimate. The root cause is a lack of validation of redirect destinations, classified as CWE‑601.

Affected Systems

All releases of the wpWax Directorist plugin from the earliest unversioned build through version 8.6.6 are affected. Administrators should verify they are using a version newer than 8.6.6 to avoid exploitation.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity, while the EPSS score of less than 1 % suggests low to very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is the use of crafted URLs with redirection parameters; the plugin accepts these without checking the target domain, allowing malicious redirects.

Generated by OpenCVE AI on April 29, 2026 at 19:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Directorist plugin to a version newer than 8.6.6.
  • If an upgrade is not feasible, disable the redirect functionality in the plugin settings or apply a server‑side rule to block untrusted redirects.
  • Implement a web application firewall or URL‑whitelisting rule to limit redirects to approved domains.

Generated by OpenCVE AI on April 29, 2026 at 19:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wpWax Directorist directorist allows Phishing.This issue affects Directorist: from n/a through <= 8.5.6. URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wpWax Directorist directorist allows Phishing.This issue affects Directorist: from n/a through <= 8.6.6.
Title WordPress Directorist plugin <= 8.5.6 - Open Redirection vulnerability WordPress Directorist plugin <= 8.6.6 - Open Redirection vulnerability

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Tue, 16 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpwax
Wpwax directorist
Vendors & Products Wordpress
Wordpress wordpress
Wpwax
Wpwax directorist

Tue, 16 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 08:30:00 +0000

Type Values Removed Values Added
Description URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wpWax Directorist directorist allows Phishing.This issue affects Directorist: from n/a through <= 8.5.6.
Title WordPress Directorist plugin <= 8.5.6 - Open Redirection vulnerability
Weaknesses CWE-601
References

Subscriptions

Wordpress Wordpress
Wpwax Directorist
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:12.731Z

Reserved: 2025-10-29T03:08:17.828Z

Link: CVE-2025-64250

cve-icon Vulnrichment

Updated: 2025-12-16T15:59:23.953Z

cve-icon NVD

Status : Deferred

Published: 2025-12-16T09:15:54.807

Modified: 2026-04-27T16:16:37.713

Link: CVE-2025-64250

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T19:15:18Z

Weaknesses