AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16590

MEDIUM · CVSS 6.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-08 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The WP Directory Kit plugin for WordPress, prior to version 1.5.5, lacks proper authorization and nonce checks on certain authenticated AJAX actions, enabling any authenticated user, including those with low-level permissions like Subscribers, to access and retrieve stored contact messages and sensitive user data from other accounts. This vulnerability poses a significant risk to user privacy and data integrity. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.

CVE
CVE-2026-16590
Severity
MEDIUM
CVSS
6.5
EPSS
0.22%
WordPress

Original NVD Description

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to retrieve stored contact messages and associated user data belonging to other users.