What is CVE-2026-16590?
CVE-2026-16590 describes a vulnerability in the WP Directory Kit WordPress plugin before version 1.5.5, where an authenticated AJAX action lacks authorization and nonce checks. This allows any authenticated user, such as a Subscriber, to retrieve stored contact messages and associated user data belonging to other users. Updating the plugin to version 1.5.5 or higher is strongly recommended.
Azərbaycanca: CVE-2026-16590 WP Directory Kit WordPress plugin-inin 1.5.5-dən əvvəlki versiyalarında avtorizasiya və nonce yoxlaması edilməyən AJAX əməliyyatını təsvir edir. Bu zəiflik Subscriber kimi autentifikasiya olunmuş istənilən istifadəçiyə digər istifadəçilərə məxsus saxlanılan əlaqə mesajlarını və əlaqəli istifadəçi məlumatlarını əldə etməyə imkan verir. Plugin-i dərhal 1.5.5 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What privilege level of user can exploit the CVE-2026-16590 vulnerability?
Any authenticated user, such as a Subscriber, can exploit the vulnerability.
To which version should the WP Directory Kit plugin be updated to fix this security issue?
Updating the plugin to version 1.5.5 or higher is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.