SQL Injection Vulnerability in DirectoryPress Business Directory Plugin by WordPress
CVE-2026-3489

7.5HIGH

What is CVE-2026-3489?

The DirectoryPress plugin for WordPress is susceptible to SQL Injection due to inadequate escaping of the 'packages' parameter. This vulnerability affects versions up to 3.6.26 and allows unauthenticated attackers to inject malicious SQL queries. Consequently, attackers can extract sensitive data from the database, potentially compromising the integrity of the site and its users.

Affected Version(s)

DirectoryPress – Business Directory And Classified Ad Listing 0 <= 3.6.26

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Leonid Semenenko
.