CVE-2026-27387: WordPress DirectoryPress plugin <= 3.6.26 - Broken Access Control vulnerability
Missing Authorization vulnerability in Designinvento DirectoryPress directorypress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DirectoryPress: from n/a through <= 3.6.26.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27387?
The severity of CVE-2026-27387 is critical due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2026-27387?
To fix CVE-2026-27387, update your DirectoryPress plugin to version 3.6.27 or later to address the missing authorization vulnerability.
What versions of DirectoryPress are affected by CVE-2026-27387?
CVE-2026-27387 affects DirectoryPress versions from n/a up to and including 3.6.26.
What are the risks of not addressing CVE-2026-27387?
Failure to address CVE-2026-27387 can lead to unauthorized users gaining access to restricted areas of your DirectoryPress site.
Who should be concerned about CVE-2026-27387?
All users and administrators of DirectoryPress versions 3.6.26 and below should be concerned about CVE-2026-27387 due to its potential risks.