CVE-2026-77766
Directorist 8.5 - 8.9.4 - Subscriber+ Order and Financial Record Disclosure via REST Orders Endpoint
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting user, allowing users with a subscriber-level account to read every customer's order and payment records. Versions 8.8.1 to 8.9 are not affected. The endpoint was scoped correctly in 8.8.1 and the unscoped behaviour was reintroduced in 8.9.1.
| Vendor | unknown |
| Product | directorist: ai-powered business directory, listings & classified ads |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown directorist: ai-powered business directory, listings & classified ads
Be the first to know when new unknown vulnerabilities affecting unknown directorist: ai-powered business directory, listings & classified ads are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Directorist: AI-Powered Business Directory, Listings & Classified Ads
8.5 < 8.9.5
References
Credits
Shivamani Vastrala WPScan