SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-18232

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The WP Directory Kit plugin for WordPress, up to version 1.5.7, is vulnerable due to inadequate access controls on its public AJAX actions, enabling unauthenticated attackers to access draft and unapproved listings from other users. This exposure could lead to unauthorized information disclosure, potentially compromising user privacy and content integrity. WordPress site administrators using this plugin should prioritize updating to a patched version to mitigate these risks.

CVE
CVE-2026-18232
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%
WordPress

Original NVD Description

The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved listings belonging to other users.