The Directorist plugin for WordPress is not secure in versions up to 7.5.4. This means someone with limited access, such as a subscriber, can delete posts they shouldn’t be able to. This is because the plugin didn’t check properly to make sure only authorized people can delete posts.