CVE-2026-77766

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/09/2026
Last modified:
23/09/2026

Description

The Directorist: AI-Powered Business Directory, Listings &amp; Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting user, allowing users with a subscriber-level account to read every customer&amp;#39;s order and payment records.<br /> <br /> Versions 8.8.1 to 8.9 are not affected. The endpoint was scoped correctly in 8.8.1 and the unscoped behaviour was reintroduced in 8.9.1.