CVE-2026-84066EPSS p10.1%

CVE-2026-84066CVE-2026-84066

Description

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above to overwrite image metadata on posts belonging to other users.

Scoring

CVSS 3.1 ()
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS0.21% probability of exploitation · percentile 10.1% · 2026-10-05T12:00:23Z
Last modified2026-09-08
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.