Junglewise Threat Intelligence

CVE-2026-84066: Directorist Missing Authorization in Post Metadata Upload

CVE-2026-84066 · Severity: low · CVSS 3.1 · Published 2026-09-04

Technologies: Directorist. Vendors: Directorist.

Executive brief

Directorist is a WordPress plugin that powers business directory and classified ads listings. A flaw allows any subscriber-level user to overwrite metadata and images on posts belonging to other users by sending a specially crafted upload request. This could enable users to deface listings, replace images, or manipulate business information without permission.

Technical details

The plugin's atbdp_post_attachment_upload AJAX action fails to verify that the requesting user owns or has permission to edit the target post before writing uploaded file references to its metadata. An attacker with subscriber role can extract a valid upload nonce from the Add Listing page, then craft a multipart POST request to /wp-admin/admin-ajax.php targeting any post ID with parameters including the nonce, post_id, and a file upload. The vulnerability allows arbitrary underscore-prefixed meta keys to be overwritten with image URLs on any post, including those owned by other users. In version 8.9, the vulnerability was patched by adding an edit_post capability check before processing uploads.

Affected products

  • Directorist Directorist before 8.9

Timeline

  • 2026-09-02: disclosed
  • 2026-09-04: patched: Fixed in version 8.9 with edit_post capability check
  • 2026-09-04: advisory

References