Improper Access Control in Directorist Plugin for WordPress
CVE-2026-77766
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 September 2026
Badges
What is CVE-2026-77766?
The Directorist plugin for WordPress suffers from an access control flaw that allows users with a subscriber-level account to gain unauthorized access to sensitive customer data, including order and payment records. This vulnerability arises because one of the REST collection endpoints is not properly scoped to the requesting user, enabling exposure of data that should be restricted. The issue affects all versions up to 8.9.5, with the vulnerability reintroduced in version 8.9.1, despite earlier corrections in version 8.8.1.
Affected Version(s)
Directorist: AI-Powered Business Directory, Listings & Classified Ads 8.5 < 8.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.