SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-59518

CRITICAL · CVSS 9.8 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

A critical deserialization vulnerability in wpWax Directorist allows for object injection, potentially enabling attackers to execute arbitrary code within the application. This affects all versions of Directorist up to and including 8.8.2. Organizations using this plugin should prioritize immediate updates or mitigations to prevent exploitation.

CVE
CVE-2026-59518
Severity
CRITICAL
CVSS
9.8
EPSS
0.30%

Original NVD Description

Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.