SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-84066

LOW · CVSS 3.1 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Directorist plugin for WordPress versions prior to 8.9 is vulnerable as it fails to verify user ownership of posts when modifying metadata, enabling users with subscriber roles and higher to overwrite image metadata on posts owned by others. This could lead to unauthorized alterations of content, potentially impacting the integrity of user-generated data. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-84066
Severity
LOW
CVSS
3.1
EPSS
0.13%
WordPress

Original NVD Description

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above to overwrite image metadata on posts belonging to other users.