---
id: CVE-2026-77766
title: >-
  The Directorist: AI-Powered Business Directory, Listings & Classified Ads
  WordPress plugin before 8.9.5 does not scope one of its REST collection
  endpoints to the requesting user, allowing users with a subscriber-level
  account to read ev…
summary: >-
  The Directorist: AI-Powered Business Directory, Listings & Classified Ads
  WordPress plugin before 8.9.5 does not scope one of its REST collection
  endpoints to the requesting user, allowing users with a subscriber-level
  account to read ev…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-639
product: 'Directorist: AI-Powered Business Directory, Listings & Classified Ads'
affected:
  - >-
    directorist_ai-powered_business_directory_listings_classified_ads >= 8.5 <
    8.9.5
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:13:31.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77766'
references:
  - url: 'https://wpscan.com/vulnerability/1b8acd9b-8309-4453-a7f7-61a463fe9ae1/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00197
epssPercentile: 0.08373
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-23T10:46:31.280420Z'
ingestedAt: '2026-09-23T06:17:57.885Z'
---

## Overview

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting user, allowing users with a subscriber-level account to read every customer's order and payment records.

Versions 8.8.1 to 8.9 are not affected. The endpoint was scoped correctly in 8.8.1 and the unscoped behaviour was reintroduced in 8.9.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
