๐Ÿ” CVE Alert

CVE-2026-84026

UNKNOWN 0.0

Directorist 8.1 - 8.9.4 - Unauthenticated Sensitive Data Disclosure via REST Users Endpoint

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restrict access to a REST endpoint that returns user records, allowing unauthenticated attackers to read registered users' private contact details.

Vendor unknown
Product directorist: ai-powered business directory, listings & classified ads
Published Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for unknown directorist: ai-powered business directory, listings & classified ads

Be the first to know when new unknown vulnerabilities affecting unknown directorist: ai-powered business directory, listings & classified ads are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Directorist: AI-Powered Business Directory, Listings & Classified Ads
8.1 < 8.9.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/4311f66d-f032-4753-88e8-2afbd5d73ebc/

Credits

Usama Arshad WPScan