๐Ÿ” CVE Alert

CVE-2026-84098

UNKNOWN 0.0

Directorist 3.1.0 - 8.9.4 - Subscriber+ Arbitrary Listing Deletion via remove_listing

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated attackers with Subscriber-level access and above to delete arbitrary listings, including ones belonging to other users. This is an incomplete fix of CVE-2023-1889 / CVE-2023-35052: a separate, unaddressed listing-deletion path allows the same impact, from at least version 3.1.0 through the current release.

Vendor unknown
Product directorist: ai-powered business directory, listings & classified ads
Published Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for unknown directorist: ai-powered business directory, listings & classified ads

Be the first to know when new unknown vulnerabilities affecting unknown directorist: ai-powered business directory, listings & classified ads are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Directorist: AI-Powered Business Directory, Listings & Classified Ads
3.1.0 < 8.9.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/b5f83718-84ff-49e4-9ad7-395cc0ab494b/

Credits

Artus KG WPScan