CVE-2026-77757
Directorist 8.5 - 8.9.2 - Subscriber+ Arbitrary Image Move via REST v2 Listing Submission
CVSS Score
5.4
EPSS Score
0.2%
EPSS Percentile
9th
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.3 does not sanitize a user-supplied image reference before using it as the source of a file move, allowing users with a subscriber-level account to relocate arbitrary server-readable image files into a publicly accessible directory, and to delete them from their original location.
| Vendor | unknown |
| Product | directorist: ai-powered business directory, listings & classified ads |
| Published | Aug 26, 2026 |
| Last Updated | Aug 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown directorist: ai-powered business directory, listings & classified ads
Be the first to know when new medium vulnerabilities affecting unknown directorist: ai-powered business directory, listings & classified ads are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Directorist: AI-Powered Business Directory, Listings & Classified Ads
8.5 < 8.9.3
References
Credits
Revanth Hari Narayana Matte WPScan