CVE-2026-16595
Received Received - Intake

Unauthorized User Data Exposure in WP Directory Kit WordPress Plugin

Vulnerability report for CVE-2026-16595, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-08

Last updated on: 2026-08-08

Assigner: WPScan

Description

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpublished listings belonging to other users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-08
Last Modified
2026-08-08
Generated
2026-08-08
AI Q&A
2026-08-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_directory_kit wp_directory_kit to 1.5.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WP Directory Kit WordPress plugin before version 1.5.5 has a vulnerability where it fails to perform authorization or nonce checks on an authenticated AJAX action. This allows any authenticated user, including those with Subscriber-level access, to access sensitive data such as the site's user list and unpublished listings created by other users.

Detection Guidance

Check if the WP Directory Kit plugin version is below 1.5.5. Log in as a Subscriber or higher and attempt to access the vulnerable AJAX action to see if user lists or unpublished listings are disclosed.

Impact Analysis

This vulnerability can lead to unauthorized disclosure of sensitive information. Attackers could access the full list of site users and view unpublished listings from other users, potentially exposing private or confidential data.

Compliance Impact

This vulnerability could lead to non-compliance with data protection regulations like GDPR or HIPAA by exposing personal or sensitive user data without authorization. Organizations may face legal penalties or reputational damage if such data breaches occur.

Mitigation Strategies

Update the WP Directory Kit plugin to version 1.5.5 or later immediately to patch the missing authorization and nonce checks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16595. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart