CVE-2026-77766 PUBLISHED

Directorist 8.5 - 8.9.4 - Subscriber+ Order and Financial Record Disclosure via REST Orders Endpoint

Assigner: WPScan
Reserved: 21.08.2026 Published: 23.09.2026 Updated: 23.09.2026

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting user, allowing users with a subscriber-level account to read every customer's order and payment records.

Versions 8.8.1 to 8.9 are not affected. The endpoint was scoped correctly in 8.8.1 and the unscoped behaviour was reintroduced in 8.9.1.

Product Status

Vendor Unknown
Product Directorist: AI-Powered Business Directory, Listings & Classified Ads
Versions Default: unaffected
  • affected from 8.5 to 8.9.5 (excl.)

Credits

  • Shivamani Vastrala finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE