CVE-2026-39531PoC

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-04-27); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-27: 1Mentions · 2026-05-22: 1PoC Mentioned / Linked · 2026-04-27: 1Patch / Workaround · 2026-05-22: 1Technical Details · 2026-04-27: 1Technical Details · 2026-05-22: 104-2705-22
Signal classification2 categories
PoC
150.0%
Patch
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-04-271
PoC1
2026-05-221
Patch1
Full discourse2 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-39531 | CVSS 9.3 SQL Injection in WP Directory Kit plugin (≤1.5.0). Network exploitable, no auth required. Blind SQLi allows high confidentiality impact. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/0KML4w1E10

    Post summary

    The tweet publicly discloses a critical SQL injection flaw in WP Directory Kit that can be exploited over the network without authentication, and urges users to apply the available patch immediately.

    0000050
    30 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-39531-wpdirectorykit-version-1-5-0-high-vulnerability-proof-of-concept CVE-2026-39531 wpdirectorykit (CVSS Score 7.5) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The entry links to a proof‑of‑concept for CVE‑2026‑39531 affecting WPDirectoryKit, including a CVSS score, but it provides no evidence of active exploitation, patch availability, or false positive status.

    0000035
    6 followersView on X

Explore more