Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-59518: Directorist 8.8.2 Deserialization of Untrusted Data Risk

CVE-2026-59518 CVE-2026-59518
Summary

The Directorist software has a security issue that could allow an attacker to inject malicious code. This affects versions up to 8.8.2, which means you should update to a newer version to stay secure. If you can't update right away, consider disabling the feature that's vulnerable until you can patch it.

What to do
  • Update wpwax directorist to version 8.8.3.
Affected software
VendorProductAffected versions
wpwax directorist <= 8.8.2
Fix: upgrade to 8.8.3
Original title
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.
Original description
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.
nvd CVSS3.1 9.8
Vulnerability type
CWE-502 Deserialization of Untrusted Data
Published: 13 Jul 2026 · Updated: 17 Jul 2026 · First seen: 13 Jul 2026