Junglewise Threat Intelligence

CVE-2026-84150: Directorist authorization bypass in REST favorites endpoint

CVE-2026-84150 · Severity: medium · CVSS 5.4 · Published 2026-09-23

Technologies: Directorist. Vendors: Directorist.

Executive brief

Directorist is a WordPress plugin that powers business directory and classified ads listings. The plugin fails to verify user identity when accessing the favorites API, allowing any logged-in subscriber to view and modify other users' favorite listings. An attacker could discover competitors' saved business listings or sabotage their saved searches.

Technical details

The REST API endpoint for user favorites does not validate that the authenticated user matches the target user ID before returning or modifying favorite records, resulting in an insecure direct object reference (IDOR). This affects any subscriber-level user on a WordPress site running the plugin. The vulnerability is fixed in version 8.9.5.

Affected products

  • Directorist Directorist before 8.9.5

Timeline

  • 2026-09-21: disclosed
  • 2026-09-23: patched: Version 8.9.5 released

References

Related threats