Directorist 8.9.1 - 8.9.4 - Subscriber+ Paid Order and Payment Record Forgery via REST Orders Endpoint
Summary
| CVE | CVE-2026-84027 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-23 06:17:02 UTC |
| Updated | 2026-09-23 06:17:02 UTC |
| Description | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, allowing users with the subscriber role and above to create paid order and payment records with arbitrary amounts and attribute them to other users. |
Risk And Classification
Problem Types: CWE-862 Missing Authorization
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | Directorist AI-Powered Business Directory Listings Classified Ads | affected 8.9.1 8.9.5 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/dff1eca0-3fdd-4e7f-8ad2-1fa52b3b4a80 | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: LevinityCyber (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.