Description
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above to overwrite image metadata on posts belonging to other users.
Published: 2026-09-04
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Post Metadata Modification
Action: Apply patch
AI Analysis

Impact

The vulnerability exists in the Directorist WordPress plugin version prior to 8.9 where the system does not verify ownership of a post before writing uploaded file references to its metadata. A user with the subscriber role or higher can therefore overwrite image metadata on posts belonging to other users, enabling unauthorized modification of content data. This represents an authorization bypass that allows altered or deleted media associations, potentially disrupting listings or compromising the integrity of posted information.

Affected Systems

The affected system is the Directorist WordPress plugin, labeled as Directorist: AI‑Powered Business Directory, Listings & Classified Ads, specifically any installations running a version earlier than 8.9.

Risk and Exploitability

The vulnerability permits an authenticated user of the subscriber tier or above to modify other users’ post metadata, a high‑impact data integrity issue. Based on the EPSS score of < 1% and KEV not listed, it is inferred that there are no publicly known exploits at this time. Based on the description, it is inferred that the exploit requires only legitimate authentication and access to the upload function that is exposed to subscribers and higher roles. Because the plugin grants upload capabilities without post‑ownership checks, it is inferred that an attacker can trivially perform the attack if the site allows unauthenticated subscribers to access the upload endpoint. The CVSS score is 3.1, indicating a low overall severity, but the potential impact on data integrity warrants attention.

Generated by OpenCVE AI on September 4, 2026 at 14:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Directorist plugin to version 8.9 or later, which contains the ownership verification fix
  • If an update cannot be performed immediately, disable or limit the atbdp_post_attachment_upload functionality by removing the corresponding endpoint or setting from the plugin configuration
  • Restrict the subscriber role’s capabilities for uploading media, for example by creating a custom role without the upload capability or by using a role‑management plugin to revoke that permission

Generated by OpenCVE AI on September 4, 2026 at 14:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Fri, 04 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above to overwrite image metadata on posts belonging to other users.
Title Directorist < 8.9 - Subscriber+ Arbitrary Post Meta Write via atbdp_post_attachment_upload
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-04T12:43:31.577Z

Reserved: 2026-09-01T06:04:09.308Z

Link: CVE-2026-84066

cve-icon Vulnrichment

Updated: 2026-09-04T12:43:23.872Z

cve-icon NVD

Status : Deferred

Published: 2026-09-04T07:17:10.940

Modified: 2026-09-08T19:15:18.627

Link: CVE-2026-84066

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T14:45:18Z

Weaknesses