CVE-2026-84098: CWE-863 Incorrect Authorization in Directorist: AI-Powered Business Directory, Listings & Classified Ads
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated attackers with Subscriber-level access and above to delete arbitrary listings, including ones belonging to other users. This is an incomplete fix of CVE-2023-1889 / CVE-2023-35052: a separate, unaddressed listing-deletion path allows the same impact, from at least version 3.1.0 through the current release.
AI Analysis
Technical Summary
CVE-2026-84098 describes an incorrect authorization vulnerability (CWE-863) in the Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin. Versions from 3.1.0 up to but not including 8.9.5 do not properly verify ownership before allowing deletion of listings. Authenticated users with Subscriber-level privileges or higher can exploit this to delete listings belonging to other users. This issue is a continuation of earlier vulnerabilities (CVE-2023-1889 and CVE-2023-35052) that were only partially fixed, leaving a separate deletion path vulnerable.
Potential Impact
Authenticated users with minimal privileges (Subscriber-level and above) can delete listings they do not own, potentially leading to unauthorized data removal and disruption of business directory content. This could affect the integrity and availability of listings managed through the plugin.
Mitigation Recommendations
Upgrade the Directorist plugin to version 8.9.5 or later, where this authorization issue has been addressed. No other mitigation is indicated by the vendor advisory. Until updated, restrict user roles to trusted users only to limit potential exploitation.
CVE-2026-84098: CWE-863 Incorrect Authorization in Directorist: AI-Powered Business Directory, Listings & Classified Ads
Description
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated attackers with Subscriber-level access and above to delete arbitrary listings, including ones belonging to other users. This is an incomplete fix of CVE-2023-1889 / CVE-2023-35052: a separate, unaddressed listing-deletion path allows the same impact, from at least version 3.1.0 through the current release.
CVSS v3.1
Score 6.5medium
Affected software
Directorist: AI-Powered Business Directory, Listings & Classified Ads
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-84098 describes an incorrect authorization vulnerability (CWE-863) in the Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin. Versions from 3.1.0 up to but not including 8.9.5 do not properly verify ownership before allowing deletion of listings. Authenticated users with Subscriber-level privileges or higher can exploit this to delete listings belonging to other users. This issue is a continuation of earlier vulnerabilities (CVE-2023-1889 and CVE-2023-35052) that were only partially fixed, leaving a separate deletion path vulnerable.
Potential Impact
Authenticated users with minimal privileges (Subscriber-level and above) can delete listings they do not own, potentially leading to unauthorized data removal and disruption of business directory content. This could affect the integrity and availability of listings managed through the plugin.
Mitigation Recommendations
Upgrade the Directorist plugin to version 8.9.5 or later, where this authorization issue has been addressed. No other mitigation is indicated by the vendor advisory. Until updated, restrict user roles to trusted users only to limit potential exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-01T06:57:59.213Z
- State
- PUBLISHED
Threat ID: 6ab36d3ff7a7c541065abca1
Added to database: 09/23/2026, 06:10:07 UTC
Last enriched: 09/23/2026, 06:32:58 UTC
Last updated: 09/24/2026, 01:57:05 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.