CVE-2026-77766
Received Received - Intake

Unauthorized Data Exposure in Directorist WordPress Plugin

Vulnerability report for CVE-2026-77766, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: WPScan

Description

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting user, allowing users with a subscriber-level account to read every customer's order and payment records. Versions 8.8.1 to 8.9 are not affected. The endpoint was scoped correctly in 8.8.1 and the unscoped behaviour was reintroduced in 8.9.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
directorist directorist to 8.9.5 (exc)
directorist directorist From 8.9.1 (inc)
directorist directorist to 8.9.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Directorist WordPress plugin versions 8.5 to 8.9.4. It involves a REST Orders endpoint that does not restrict access based on user roles, allowing subscribers to view all customer order and financial records. The issue was reintroduced in version 8.9.1 after being fixed in 8.8.1.

Detection Guidance

Check WordPress sites running Directorist versions 8.5 to 8.9.4 for unauthorized access to order and payment records via the REST Orders endpoint. Monitor logs for unusual subscriber-level access to sensitive data endpoints.

Impact Analysis

If you use the Directorist plugin in versions 8.5 to 8.9.4, a subscriber-level user could access and view sensitive customer order and payment data. This could lead to unauthorized exposure of financial information and personal details.

Compliance Impact

This vulnerability could violate GDPR and HIPAA by exposing personal and financial data to unauthorized users. GDPR requires protecting personal data, while HIPAA mandates safeguarding protected health information. Unauthorized access risks non-compliance and potential legal penalties.

Mitigation Strategies

Update Directorist to version 8.9.5 or later immediately to patch the vulnerability. Review user roles and permissions to ensure subscribers do not have unnecessary access to sensitive endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77766. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart