Impact
The vulnerability lies in the Directorist WordPress plugin’s REST API which fails to verify user capabilities when an order is created. A user with the subscriber role or higher can submit an order request specifying any monetary amount and associate the order with any user account, thereby forging payment records. This flaw permits unauthenticated or low‑privileged users to generate fraudulent transactions that could lead to financial loss, reputational damage, and confusion of the site’s reporting system.
Affected Systems
WordPress sites running Directorist versions 8.9.1 through 8.9.4, or any earlier build before the 8.9.5 release, are vulnerable. The flaw affects all users who hold the subscriber role or a higher privilege level, as they can invoke the compromised REST endpoint to create orders for any account on the site.
Risk and Exploitability
The flaw receives a CVSS score of 4.3, indicating a moderate impact. The EPSS score is not available, and the vulnerability is not included in the CISA KEV catalog. Attackers can exploit the issue simply by sending a crafted REST request; no additional system compromise or exploitation of additional code paths is required. Because subscriber accounts are often granted to legitimate users, the risk is primarily from insider or compromised low‑privilege accounts.
OpenCVE Enrichment