WordPress Plugin Vulnerabilities

Directorist 8.9.1 - 8.9.4 - Subscriber+ Paid Order and Payment Record Forgery via REST Orders Endpoint

Description

The plugin does not check user capabilities when creating orders through its REST API, allowing users with the subscriber role and above to create paid order and payment records with arbitrary amounts and attribute them to other users.

Proof of Concept

Affects Plugins

Fixed in 8.9.5

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
LevinityCyber
Submitter
LevinityCyber
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-09-21 (about 2 days ago)
Added
2026-09-21 (about 1 day ago)
Last Updated
2026-09-21 (about 1 day ago)

Other