CVE-2026-39566 PUBLISHED

WordPress DirectoryPress plugin <= 3.6.26 - Sensitive Data Exposure vulnerability

Assigner: Patchstack
Reserved: 07.04.2026 Published: 08.04.2026 Updated: 08.04.2026

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Designinvento DirectoryPress directorypress allows Retrieve Embedded Sensitive Data.This issue affects DirectoryPress: from n/a through <= 3.6.26.

Product Status

Vendor Designinvento
Product DirectoryPress
Versions Default: unaffected
  • affected from 0 to 3.6.26 (incl.)

Credits

  • Bao - BlueRock | Patchstack Bug Bounty Program finder

References

Problem Types

  • Exposure of Sensitive System Information to an Unauthorized Control Sphere CWE

Impacts

  • Retrieve Embedded Sensitive Data