Junglewise Threat Intelligence

CVE-2026-39566: Designinvento DirectoryPress sensitive information disclosure

CVE-2026-39566 · Severity: medium · CVSS 4.3 · Published 2026-04-08

Executive brief

DirectoryPress is a WordPress plugin used to create and manage business directories and classified listing websites. A security flaw in this plugin allows unauthorized individuals to access sensitive system information that should be restricted. This exposure could provide attackers with technical details needed to launch more sophisticated attacks against the website or its users.

Technical details

The DirectoryPress plugin for WordPress (versions up to and including 3.6.26) is vulnerable to 'Exposure of Sensitive System Information to an Unauthorized Control Sphere' (CWE-497). The vulnerability allows an attacker to retrieve embedded sensitive data from the system. While some metrics suggest a low-privileged user account is required (PR:L), other assessments indicate it may be reachable by unauthenticated users. The flaw was addressed in version 3.6.27.

Affected products

  • Designinvento DirectoryPress <= 3.6.26

Timeline

  • 2026-02-21: other: Reported by researcher
  • 2026-03-23: advisory: Patchstack advisory published
  • 2026-04-08: disclosed: CVE published
  • 2026-03-23: patched: Version 3.6.27 released

References