What is CVE-2026-16589?
CVE-2026-16589 is a vulnerability in the WP Directory Kit WordPress plugin before version 1.5.5 that allows any authenticated user, such as a Subscriber, to perform SQL injection via an AJAX action due to lack of authorization and nonce checks. Updating to version 1.5.5 or later is recommended.
Azərbaycanca: CVE-2026-16589, WP Directory Kit WordPress plaginində autentifikasiya olunmuş istənilən istifadəçiyə (məsələn, Subscriber) SQL injection həyata keçirməyə imkan verən boşluqdur. 1.5.5 versiyasından əvvəlki versiyalar təsirlənir və plaginin yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the WP Directory Kit plugin are affected by CVE-2026-16589?
All versions of the plugin before version 1.5.5 are affected.
What level of user access is required to exploit CVE-2026-16589?
Any authenticated user, such as a Subscriber, is sufficient to exploit the vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.