Executive brief
wpWax Directorist, a WordPress plugin used to create business directories and classified listing sites, contains a security flaw in its access control settings. This vulnerability allows unauthorized users to bypass intended security levels, potentially leading to unauthorized modifications of directory data. While the impact is considered limited, it could allow attackers to interfere with how listings are managed or displayed on the site.
Technical details
A missing authorization vulnerability (CWE-862) exists in the wpWax Directorist plugin for WordPress through version 8.5.10. The flaw resides in the plugin's failure to properly validate authorization or security levels for certain functions, allowing unauthenticated remote attackers to execute actions that should be restricted. According to the CVSS vector, the attack has low complexity and requires no user interaction, primarily impacting data integrity rather than confidentiality or availability. The issue is addressed in version 8.6.1.
Affected products
- wpWax Directorist <= 8.5.10
Timeline
- 2026-01-23: other: Reported by researcher johska
- 2026-02-22: advisory: Patchstack advisory published
- 2026-04-08: disclosed: CVE published to NVD
- 2026-08-06: patched: Fixed in version 8.6.1