The Directorist for WordPress is a website plugin that had a security flaw in versions up to 7.5.3. This flaw allowed people with administrator privileges to include and execute any file they wished on the server. That file could contain any code, which could be used to get around security restrictions, access sensitive data, or even execute code where images or other “safe” file types can be uploaded and included.