Loading market data...
← Back to CVE feed

CVE-2026-84066

LOW CVSS 3.1 View on NVD ↗

Description

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above to overwrite image metadata on posts belonging to other users.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Published: Sep 04, 2026 07:17 UTC Modified: Sep 04, 2026 13:20 UTC