CyberRota Analysis
AI-GeneratedThe Directorist plugin for WordPress versions prior to 8.9 is vulnerable as it fails to verify user ownership of posts when modifying metadata, enabling users with subscriber roles and higher to overwrite image metadata on posts owned by others. This could lead to unauthorized alterations of content, potentially impacting the integrity of user-generated data. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above to overwrite image metadata on posts belonging to other users.