AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16595

MEDIUM · CVSS 6.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-08 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The WP Directory Kit plugin for WordPress prior to version 1.5.5 lacks proper authorization and nonce checks on an authenticated AJAX action, enabling any authenticated user, including those with minimal permissions like Subscribers, to access sensitive information such as the site's user list and unpublished listings of other users. This vulnerability poses a significant risk to user privacy and data integrity. WordPress site administrators and security teams should prioritize updating to the latest version of the plugin to mitigate potential data exposure.

CVE
CVE-2026-16595
Severity
MEDIUM
CVSS
6.5
EPSS
0.22%
WordPress

Original NVD Description

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpublished listings belonging to other users.