Description
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, allowing users with the subscriber role and above to create paid order and payment records with arbitrary amounts and attribute them to other users.
Published: 2026-09-23
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized creation of paid orders and payment records
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the Directorist WordPress plugin’s REST API which fails to verify user capabilities when an order is created. A user with the subscriber role or higher can submit an order request specifying any monetary amount and associate the order with any user account, thereby forging payment records. This flaw permits unauthenticated or low‑privileged users to generate fraudulent transactions that could lead to financial loss, reputational damage, and confusion of the site’s reporting system.

Affected Systems

WordPress sites running Directorist versions 8.9.1 through 8.9.4, or any earlier build before the 8.9.5 release, are vulnerable. The flaw affects all users who hold the subscriber role or a higher privilege level, as they can invoke the compromised REST endpoint to create orders for any account on the site.

Risk and Exploitability

The flaw receives a CVSS score of 4.3, indicating a moderate impact. The EPSS score is not available, and the vulnerability is not included in the CISA KEV catalog. Attackers can exploit the issue simply by sending a crafted REST request; no additional system compromise or exploitation of additional code paths is required. Because subscriber accounts are often granted to legitimate users, the risk is primarily from insider or compromised low‑privilege accounts.

Generated by OpenCVE AI on September 23, 2026 at 14:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Directorist to version 8.9.5 or later, which adds capability checks to the REST order endpoint.
  • Disable or secure the REST orders endpoint, ensuring only users with the "manage_options" capability can create or modify orders.
  • Audit user roles and adjust the subscriber role to prevent order creation, or enforce stricter access control at the REST API level.
  • Monitor the order logs for anomalous or high‑volume payment record creations to detect potential misuse early.

Generated by OpenCVE AI on September 23, 2026 at 14:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, allowing users with the subscriber role and above to create paid order and payment records with arbitrary amounts and attribute them to other users.
Title Directorist 8.9.1 - 8.9.4 - Subscriber+ Paid Order and Payment Record Forgery via REST Orders Endpoint
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-23T10:58:07.267Z

Reserved: 2026-09-01T01:46:40.339Z

Link: CVE-2026-84027

cve-icon Vulnrichment

Updated: 2026-09-23T10:37:22.323Z

cve-icon NVD

Status : Received

Published: 2026-09-23T06:17:02.840

Modified: 2026-09-23T11:17:12.617

Link: CVE-2026-84027

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T14:30:06Z

Weaknesses