Impact
This vulnerability allows a subscriber-level user to read every customer's order and payment records via a REST endpoint that was incorrectly unscoped. The lack of proper authorization checks permits disclosure of confidential transaction data, which is a confidentiality violation. The weakness is identified as CWE-639, Authorization Bypass Through User-Controlled Key.
Affected Systems
The Directorist AI‑Powered Business Directory WordPress plugin is affected in versions 8.5 through 8.7.x and 8.9.1 through 8.9.4. Versions 8.8.1 to 8.9, as well as 8.9.5 and later, correctly scope the endpoint and are not impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk, and the lack of an EPSS score or KEV listing suggests no widely available exploits. The attack vector relies on authenticated subscriber access to the REST Orders endpoint, making the vulnerability exploitable by any user who can log in as a subscriber. Although the impact is limited to confidentiality, the widespread availability of subscriber accounts raises the overall risk to the organization.
OpenCVE Enrichment