CVE-2026-84046: Directorist < 8.9.5 - Subscriber+ SSRF via Avatar URL
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validate a user-supplied URL before fetching it server-side, allowing users with the subscriber role and above to make the server issue requests to internal addresses.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user with the subscriber role or a higher-privileged role can supply a URL that the server fetches. Unauthenticated visitors are not identified as able to exploit it by the available data.
What access does an attacker need?
The attacker needs an account with at least the subscriber role and the ability to provide the affected avatar URL. Exploitation relies on the server making the request, which can expose access to internal addresses reachable from that server.
Which versions are affected?
Directorist versions before 8.9.5 are affected. Updating to version 8.9.5 or later addresses the affected version range described here.