CVE-2026-84098 Details
Description
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated attackers with Subscriber-level access and above to delete arbitrary listings, including ones belonging to other users. This is an incomplete fix of CVE-2023-1889 / CVE-2023-35052: a separate, unaddressed listing-deletion path allows the same impact, from at least version 3.1.0 through the current release.
A vulnerability exists in the Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin, affecting versions prior to 8.9.5. The issue arises because the plugin fails to properly verify ownership of listings before allowing them to be deleted. This flaw enables authenticated attackers with Subscriber-level access or higher to delete any listing, including those belonging to other users. This vulnerability represents an incomplete fix of CVE-2023-1889 and CVE-2023-35052, as a separate, unaddressed deletion path continues to allow similar exploitation.
Users are advised to update the Directorist WordPress plugin to version 8.9.5 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 23, 2026CISA-ADP
Assessed Sep 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/b5f83718-84ff-49e4-9ad7-395cc0ab494b/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Directorist | >= 3.1.0, <= 8.9.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2026 | New CVE Received | [email protected] |
Volerion