rootpwn

medium · CVSS v3 4.3 · EPSS 0.0018

CVE-2026-77766

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope o…

Description

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting user, allowing users with a subscriber-level account to read every customer's order and payment records. Versions 8.8.1 to 8.9 are not affected. The endpoint was scoped correctly in 8.8.1 and the unscoped behaviour was reintroduced in 8.9.1.

Scores

Severity
medium
CVSS v2
4
CVSS v3
4.3
CVSS v4
EPSS
0.0018

← All CVEs