CVE-2026-84066

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above to overwrite image metadata on posts belonging to other users.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 07:17

Updated : 2026-09-08 19:15


NVD link : CVE-2026-84066

Mitre link : CVE-2026-84066

CVE.ORG link : CVE-2026-84066


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization