SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16592

LOW · CVSS 2.7 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The WP Directory Kit plugin for WordPress, up to version 1.5.7, is vulnerable due to inadequate authorization checks in its shortcode functionality, allowing users with Contributor roles to access and disclose non-public listing content, including sensitive information from other users. This vulnerability poses a significant risk to user privacy and data security. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential data exposure.

CVE
CVE-2026-16592
Severity
LOW
CVSS
2.7
EPSS
0.19%
WordPress

Original NVD Description

The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role as low as Contributor to disclose non-public listing content, including password-protected and hidden fields, belonging to other users.