CVE-2026-39566: WordPress DirectoryPress plugin <= 3.6.26 - Sensitive Data Exposure vulnerability
Published Apr 8, 2026
·Updated
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Designinvento DirectoryPress directorypress allows Retrieve Embedded Sensitive Data.This issue affects DirectoryPress: from n/a through <= 3.6.26.
Affected Software
1 affected component
Designinvento DirectoryPress<=3.6.26
Event History
Apr 8, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39566?
The severity of CVE-2026-39566 is categorized as a medium-level vulnerability due to sensitive data exposure.
2
How do I fix CVE-2026-39566?
To fix CVE-2026-39566, update the Designinvento DirectoryPress plugin to the latest version beyond 3.6.26.
3
What type of data is at risk in CVE-2026-39566?
CVE-2026-39566 exposes sensitive system information that can be accessed by unauthorized entities.
4
Which versions of DirectoryPress are affected by CVE-2026-39566?
CVE-2026-39566 affects all versions of Designinvento DirectoryPress up to and including 3.6.26.
5
Is CVE-2026-39566 being actively exploited?
Currently, there are no reports indicating that CVE-2026-39566 is being actively exploited in the wild.