cleantalk
Vulnerabilities and Security Researches

Directorist – WordPress Business Directory Plugin with Classified Ads Listings, CVE-2026-84027

CVE, Research URL

CVE-2026-84027

Published on
Sep 23, 2026
Research Description
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, allowing users with the subscriber role and above to create paid order and payment records with arbitrary amounts and attribute them to other users.
Affected versions
Min 8.9.1, max 8.9.5.
Status
vulnerable