---
id: CVE-2026-84066
title: >-
  The Directorist: AI-Powered Business Directory, Listings & Classified Ads
  WordPress plugin before 8.9 does not verify that the requesting user owns the
  post being modified before writing uploaded file references to its metadata,
  allowing…
summary: >-
  The Directorist: AI-Powered Business Directory, Listings & Classified Ads
  WordPress plugin before 8.9 does not verify that the requesting user owns the
  post being modified before writing uploaded file references to its metadata,
  allowing…
severity: low
cvss: 3.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:15:18.627'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84066'
references:
  - url: 'https://wpscan.com/vulnerability/99d990ce-aef3-404d-8ce0-803215fbf0bb/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00209
epssPercentile: 0.10045
ingestedAt: '2026-09-08T20:10:03.163Z'
---

## Overview

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above to overwrite image metadata on posts belonging to other users.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
