CVE-2026-84066: Unknown Directorist: Ai-Powered Business Directory, Listings & Classified Ads
Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above to overwrite image metadata on posts belonging to other users.
Affected products
- Unknown Directorist: Ai-Powered Business Directory, Listings & Classified Ads: before 8.9 (fixed in 8.9)
Published 2026-09-04. Last modified 2026-09-08.