CVE-2026-39509: WordPress Directorist plugin <= 8.5.10 - Broken Access Control vulnerability
Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through <= 8.5.10.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wpWax Directorist (Directorist)to a version that resolves this vulnerability.Fixed in 8.5.10
Event History
Frequently Asked Questions
What systems are affected by CVE-2026-39509?
CVE-2026-39509 affects the wpWax Directorist plugin versions up to and including 8.5.10.
What is the nature of the vulnerability in CVE-2026-39509?
CVE-2026-39509 is a Broken Access Control vulnerability that allows exploitation of incorrectly configured access control security levels.
What potential impact does CVE-2026-39509 have?
Exploiting CVE-2026-39509 could allow unauthorized access to sensitive data and functionalities of the Directorist plugin.
How do I fix CVE-2026-39509?
To fix CVE-2026-39509, update the wpWax Directorist plugin to a version newer than 8.5.10.
Is there a workaround for CVE-2026-39509?
Currently, the recommended action for CVE-2026-39509 is to update the plugin, as no specific workaround is provided.