The Directorist plugin for WordPress, which helps create business directories and classified ads listings, has a vulnerability that allows hackers to take over user accounts. This is because the plugin’s functions for generating and resetting passwords do not have enough security measures to prevent a brute force attack. This means that attackers can use a special code to reset any user’s password, even an administrator’s, without being authorized to do so.