CVE-2026-59518

WordPress Directorist plugin <= 8.8.2 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.


We have discovered 929 live websites that are affected by CVE-2026-59518.

Run a Free Instant Scan




Affected Software

Product  Directorist
Category Wordpress Plugins
Vulnerable Domains929 live websites (99% of Directorist install base)
Vulnerable Versions
  • from 0 through 8.8.2
Vulnerable Versions Count78 versions ( 99% of all versions)



Details

  • Published - Jul 13, 2026
  • Updated - Jul 13, 2026

Credits

  • dutafi | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-59518
United States350 websites



Germany67 websites
France61 websites
GB50 websites
Poland31 websites
Cyprus26 websites
Spain26 websites
South Africa25 websites
Italy24 websites
Canada20 websites

Website Distribution by TLD

Number of websites using CVE-2026-59518
.com406 websites
.org95 websites
.fr33 websites
.pl26 websites
.net23 websites
.it20 websites
.de19 websites
.co.uk19 websites
.com.br17 websites
.es14 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-59518

Top websites that are affected by CVE-2026-59518. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States**,***
*******.com Singapore***,***
************.com GB***,***
*******.com United States***,***
**.*******.gov United States***,***
****.org United States***,***
****.org United States***,***
*********.org United States***,***
**************.com United States***,***
****.com United States***,***
See full domain list

FAQ

A total of 929 websites have been identified as vulnerable to CVE-2026-59518, based on global website indexing conducted by WebTechSurvey.
The Directorist is affected by the CVE-2026-59518 vulnerability.
Directorist versions up to and including 8.8.2 are vulnerable to CVE-2026-59518.