๐Ÿ” CVE Alert

CVE-2026-77766

UNKNOWN 0.0

Directorist 8.5 - 8.9.4 - Subscriber+ Order and Financial Record Disclosure via REST Orders Endpoint

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting user, allowing users with a subscriber-level account to read every customer's order and payment records. Versions 8.8.1 to 8.9 are not affected. The endpoint was scoped correctly in 8.8.1 and the unscoped behaviour was reintroduced in 8.9.1.

Vendor unknown
Product directorist: ai-powered business directory, listings & classified ads
Published Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for unknown directorist: ai-powered business directory, listings & classified ads

Be the first to know when new unknown vulnerabilities affecting unknown directorist: ai-powered business directory, listings & classified ads are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Directorist: AI-Powered Business Directory, Listings & Classified Ads
8.5 < 8.9.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/1b8acd9b-8309-4453-a7f7-61a463fe9ae1/

Credits

Shivamani Vastrala WPScan