Junglewise Threat Intelligence

CVE-2026-77766: Directorist WordPress plugin REST endpoint authorization bypass

CVE-2026-77766 · Severity: medium · CVSS 4.3 · Published 2026-09-23

Technologies: Directorist. Vendors: Directorist.

Executive brief

The Directorist WordPress plugin for business directories allows low-privilege subscriber accounts to access order and payment records for all customers through an unscoped REST API endpoint. An attacker with a basic subscriber account can read sensitive financial and transactional data belonging to any customer, potentially exposing personally identifiable information and business transaction details.

Technical details

The plugin's REST orders collection endpoint fails to properly scope records to the requesting user, allowing any authenticated subscriber to enumerate and read all customer orders and payment records via an insecure direct object reference (IDOR) vulnerability. The flaw was introduced in version 8.9.1 after being correctly scoped in 8.8.1, affecting versions 8.5 through 8.9.4. An attacker needs only subscriber-level authentication to exploit the vulnerability.

Affected products

  • Directorist Directorist 8.5 to 8.9.4; 8.9 to 8.9 unaffected; fixed in 8.9.5

Timeline

  • 2026-09-21: disclosed
  • 2026-09-23: patched: Version 8.9.5 released

References

Related threats