๐Ÿ” CVE Alert

CVE-2026-84027

UNKNOWN 0.0

Directorist 8.9.1 - 8.9.4 - Subscriber+ Paid Order and Payment Record Forgery via REST Orders Endpoint

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, allowing users with the subscriber role and above to create paid order and payment records with arbitrary amounts and attribute them to other users.

Vendor unknown
Product directorist: ai-powered business directory, listings & classified ads
Published Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for unknown directorist: ai-powered business directory, listings & classified ads

Be the first to know when new unknown vulnerabilities affecting unknown directorist: ai-powered business directory, listings & classified ads are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Directorist: AI-Powered Business Directory, Listings & Classified Ads
8.9.1 < 8.9.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/dff1eca0-3fdd-4e7f-8ad2-1fa52b3b4a80/

Credits

LevinityCyber WPScan