Description
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated attackers with Subscriber-level access and above to delete arbitrary listings, including ones belonging to other users.

This is an incomplete fix of CVE-2023-1889 / CVE-2023-35052: a separate, unaddressed listing-deletion path allows the same impact, from at least version 3.1.0 through the current release.
Published: 2026-09-23
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Deletion
Action: Apply Patch
AI Analysis

Impact

The Directorist plugin does not verify that the user owns the listing before performing a delete operation, permitting any authenticated user with Subscriber or higher privileges to delete any listing regardless of ownership. This flaw is an incorrect authorization weakness (CWE‑863) and results in accidental or malicious removal of listing data, causing loss of content and potential revenue for the affected users.

Affected Systems

WordPress sites using the Directorist AI‑Powered Business Directory, Listings & Classified Ads plugin versions from 3.1.0 up to and including 8.9.4 are impacted. The vulnerability also persists in the same range via an unaddressed deletion path discussed in CVE‑2023‑1889 and CVE‑2023‑35052.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity vulnerability, while no EPSS score is available and the issue is not currently listed in CISA’s KEV catalog. Exploitation requires authenticated access with Subscriber‑level or higher privileges, so an attacker would need to compromise or spoof a legitimate user account. Consequently, the risk scenario is that compromised subscribers could intentionally or unintentionally delete listings belonging to other users, leading to data loss across the WordPress site.

Generated by OpenCVE AI on September 23, 2026 at 14:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Directorist plugin to version 8.9.5 or later, which corrects the authorization check on listing deletion.
  • If an upgrade cannot be performed immediately, remove or disable the remove_listing action for Subscriber roles so that only administrators can delete listings.
  • Consider restricting Subscriber capabilities or employing custom role management to prevent listing deletion by users below administrator level.

Generated by OpenCVE AI on September 23, 2026 at 14:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated attackers with Subscriber-level access and above to delete arbitrary listings, including ones belonging to other users. This is an incomplete fix of CVE-2023-1889 / CVE-2023-35052: a separate, unaddressed listing-deletion path allows the same impact, from at least version 3.1.0 through the current release.
Title Directorist 3.1.0 - 8.9.4 - Subscriber+ Arbitrary Listing Deletion via remove_listing
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-23T10:57:36.140Z

Reserved: 2026-09-01T06:57:59.213Z

Link: CVE-2026-84098

cve-icon Vulnrichment

Updated: 2026-09-23T10:36:57.931Z

cve-icon NVD

Status : Received

Published: 2026-09-23T06:17:03.070

Modified: 2026-09-23T11:17:12.917

Link: CVE-2026-84098

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T14:30:06Z

Weaknesses