Impact
The Directorist plugin does not verify that the user owns the listing before performing a delete operation, permitting any authenticated user with Subscriber or higher privileges to delete any listing regardless of ownership. This flaw is an incorrect authorization weakness (CWE‑863) and results in accidental or malicious removal of listing data, causing loss of content and potential revenue for the affected users.
Affected Systems
WordPress sites using the Directorist AI‑Powered Business Directory, Listings & Classified Ads plugin versions from 3.1.0 up to and including 8.9.4 are impacted. The vulnerability also persists in the same range via an unaddressed deletion path discussed in CVE‑2023‑1889 and CVE‑2023‑35052.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability, while no EPSS score is available and the issue is not currently listed in CISA’s KEV catalog. Exploitation requires authenticated access with Subscriber‑level or higher privileges, so an attacker would need to compromise or spoof a legitimate user account. Consequently, the risk scenario is that compromised subscribers could intentionally or unintentionally delete listings belonging to other users, leading to data loss across the WordPress site.
OpenCVE Enrichment