CVE-2026-39534Disclosure

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-12: 1PoC Mentioned / Linked · 2026-05-12: 1Active Exploitation · 2026-05-12: 105-12
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 #CVE-2026-39534: How One Missing Auth Check Exposed 3k WordPress Sites’ Customer Databases + Video https://undercodetesting.com/cve-2026-39534-how-one-missing-auth-check-exposed-3k-wordpress-sites-customer-databases-video/ Educational Purposes!

    Post summary

    The post announces a CVE‑2026‑39534 flaw in WordPress due to a missing authentication check that exposed the customer databases of roughly 3,000 sites, accompanied by a demonstration video but lacking explicit patches or detailed technical analysis.

    0000028
    568 followersView on X

Explore more