SQL Injection Vulnerability in DirectoryPress Business Directory Plugin by WordPress
CVE-2026-3489
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 April 2026
What is CVE-2026-3489?
The DirectoryPress plugin for WordPress is susceptible to SQL Injection due to inadequate escaping of the 'packages' parameter. This vulnerability affects versions up to 3.6.26 and allows unauthenticated attackers to inject malicious SQL queries. Consequently, attackers can extract sensitive data from the database, potentially compromising the integrity of the site and its users.
Affected Version(s)
DirectoryPress β Business Directory And Classified Ad Listing 0 <= 3.6.26