CVE-2026-84046 PUBLISHED

Directorist < 8.9.5 - Subscriber+ SSRF via Avatar URL

Assigner: WPScan
Reserved: 01.09.2026 Published: 23.09.2026 Updated: 23.09.2026

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validate a user-supplied URL before fetching it server-side, allowing users with the subscriber role and above to make the server issue requests to internal addresses.

Product Status

Vendor Unknown
Product Directorist: AI-Powered Business Directory, Listings & Classified Ads
Versions Default: unaffected
  • affected from 0 to 8.9.5 (excl.)

Credits

  • Bhaveshkumar Parmar finder
  • WPScan coordinator

References

Problem Types

  • CWE-918 Server-Side Request Forgery (SSRF) CWE