CVE-2026-39534: Wp Directory Kit
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions.
Affected products
- Wp Directory Kit Wp Directory Kit: up to and including 1.5.0
Published 2026-06-15. Last modified 2026-06-17.