Junglewise Threat Intelligence

CVE-2026-84046: Directorist AI-Powered Business Directory plugin SSRF in avatar URL

CVE-2026-84046 · Severity: medium · CVSS 5 · Published 2026-09-23

Technologies: Directorist. Vendors: Directorist.

Executive brief

The Directorist WordPress plugin, used to manage business directories and classified ads, contains a server-side request forgery (SSRF) vulnerability in its avatar URL handling. An attacker with a subscriber account or higher privilege can supply a malicious URL that forces the server to make requests to internal network addresses, potentially exposing sensitive internal services and data.

Technical details

The plugin fails to validate user-supplied URLs before fetching them server-side via the avatar URL field. Users with subscriber role and above can abuse this to perform SSRF attacks against internal addresses. An attacker gains the ability to probe internal network services, bypass firewall restrictions, and potentially read internal resources if accessible to the web server process.

Affected products

  • directorist Directorist before 8.9.5

Timeline

  • 2026-09-21: disclosed
  • 2026-09-23: patched: Fixed in version 8.9.5

References

Related threats