CVE-2026-84098: Directorist 3.1.0 - 8.9.4 - Subscriber+ Arbitrary Listing Deletion via remove_listing
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated attackers with Subscriber-level access and above to delete arbitrary listings, including ones belonging to other users.
This is an incomplete fix of CVE-2023-1889 / CVE-2023-35052: a separate, unaddressed listing-deletion path allows the same impact, from at least version 3.1.0 through the current release.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Directoristto a version that resolves this vulnerability.Fixed in 8.9.5
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated to WordPress with a Subscriber-level account or any higher-privileged role. They can target listings owned by other users.
Which versions are affected?
The affected listing-deletion path is present from at least Directorist 3.1.0 through 8.9.4. Version 8.9.5 is identified as the version that addresses this issue.
What is the impact of successful exploitation?
A qualifying authenticated user can delete arbitrary listings, including listings belonging to other users. The issue affects a separate deletion path that remained after fixes for CVE-2023-1889 and CVE-2023-35052.