The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above to overwrite image metadata on posts belonging to other users.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-04 07:17
Updated : 2026-09-08 19:15
NVD link : CVE-2026-84066
Mitre link : CVE-2026-84066
CVE.ORG link : CVE-2026-84066
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
