PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39509 wpWax CVE debrief

A Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Directorist: from n/a through <= 8.5.10. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of Directorist plugin for WordPress, version 8.5.10 or earlier, should apply patches or mitigations to prevent potential security risks.

Vendor
wpWax
Product
Directorist
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Users of Directorist plugin for WordPress, version 8.5.10 or earlier, should apply patches or mitigations to prevent potential security risks. This includes operators, platform administrators, vulnerability management teams, and security teams who need to review and configure access control security levels for Directorist plugin.

Technical summary

The CVE-2026-39509 vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. It was published on 2026-04-08T09:16:25.080Z and last modified on 2026-07-24T21:10:00.143Z. The vulnerability is related to a Missing Authorization issue in the Directorist plugin, which could allow attackers to exploit incorrectly configured access control security levels. Affected users should review official advisories and apply patches or mitigations.

Defensive priority

Apply patches or updates to Directorist plugin version 8.5.10 or earlier to mitigate potential security risks. Review and configure access control security levels for Directorist plugin. Monitor for potential security risks and anomalies in Directorist plugin usage.

Recommended defensive actions

  • Apply patches or updates to Directorist plugin version 8.5.10 or earlier.
  • Review and configure access control security levels for Directorist plugin.
  • Monitor for potential security risks and anomalies in Directorist plugin usage.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.

Evidence notes

The CVE record was published on 2026-04-08T09:16:25.080Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. The vulnerability affects Directorist plugin for WordPress, version 8.5.10 or earlier. Users should verify their deployments and review official advisories for mitigation guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-39509 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-39509

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-39509 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-39509

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.