Executive brief
Directorist is a WordPress plugin that powers business directory and classified ads listings. The plugin fails to verify user identity when accessing the favorites API, allowing any logged-in subscriber to view and modify other users' favorite listings. An attacker could discover competitors' saved business listings or sabotage their saved searches.
Technical details
The REST API endpoint for user favorites does not validate that the authenticated user matches the target user ID before returning or modifying favorite records, resulting in an insecure direct object reference (IDOR). This affects any subscriber-level user on a WordPress site running the plugin. The vulnerability is fixed in version 8.9.5.
Affected products
- Directorist Directorist before 8.9.5
Timeline
- 2026-09-21: disclosed
- 2026-09-23: patched: Version 8.9.5 released