---
id: CVE-2026-84027
title: >-
  The Directorist: AI-Powered Business Directory, Listings & Classified Ads
  WordPress plugin before 8.9.5 does not check user capabilities when creating
  orders through its REST API, allowing users with the subscriber role and above
  to crea…
summary: >-
  The Directorist: AI-Powered Business Directory, Listings & Classified Ads
  WordPress plugin before 8.9.5 does not check user capabilities when creating
  orders through its REST API, allowing users with the subscriber role and above
  to crea…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
product: 'Directorist: AI-Powered Business Directory, Listings & Classified Ads'
affected:
  - >-
    directorist_ai-powered_business_directory_listings_classified_ads >= 8.9.1 <
    8.9.5
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:13:31.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84027'
references:
  - url: 'https://wpscan.com/vulnerability/dff1eca0-3fdd-4e7f-8ad2-1fa52b3b4a80/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00185
epssPercentile: 0.072
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-23T10:43:29.813763Z'
ingestedAt: '2026-09-23T06:17:57.889Z'
---

## Overview

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, allowing users with the subscriber role and above to create paid order and payment records with arbitrary amounts and attribute them to other users.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
