CVE-2026-77766: Directorist 8.5 - 8.9.4 - Subscriber+ Order and Financial Record Disclosure via REST Orders Endpoint
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting user, allowing users with a subscriber-level account to read every customer's order and payment records.
Versions 8.8.1 to 8.9 are not affected. The endpoint was scoped correctly in 8.8.1 and the unscoped behaviour was reintroduced in 8.9.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Directoristto a version that resolves this vulnerability.Fixed in 8.9.5
Event History
Frequently Asked Questions
Which versions require remediation?
Versions before 8.8.1 are affected, as are versions 8.9.1 through 8.9.4. Versions 8.8.1 through 8.9 are not affected, and version 8.9.5 fixes the issue.
What access does an attacker need?
An attacker needs a WordPress account with at least subscriber-level permissions. No higher-privileged account is required to access the improperly scoped REST collection endpoint.
What data could be exposed?
Affected sites may disclose every customer's order records and payment records through the REST orders endpoint.