Impact
The Directorist plugin fails to validate a URL supplied by the user when fetching it server‑side. This flaw allows any authenticated user with the subscriber role or higher to cause the WordPress server to resolve and retrieve that URL. The resulting server‑side request gives the attacker the ability to contact internal addresses, potentially exposing internal services, harvesting sensitive data, or performing reconnaissance on the network. The weakness aligns with CWE‑918, indicating an SSRF vulnerability.
Affected Systems
Affected is the Directorist AI‑Powered Business Directory, Listings & Classified Ads WordPress plugin, versions prior to 8.9.5. Users with the subscriber role or higher on any installation of the plugin are at risk.
Risk and Exploitability
The CVSS score of 5.0 classifies the vulnerability as moderate. No EPSS score is provided and it is not listed in the CISA KEV catalog, suggesting that, while exploitation is possible, it is not currently tracked as a widely used exploit. An attacker must first authenticate to the WordPress site, obtain a subscriber‑level account or higher, and then supply a crafted URL. The exploit requires only the ability to submit or update an avatar URL, a function that is exposed to subscribers and above.
OpenCVE Enrichment