What is CVE-2026-16594?
CVE-2026-16594 is a vulnerability in the WP Directory Kit WordPress plugin before version 1.5.5. Due to missing authorization and nonce checks on an authenticated AJAX action, any authenticated user like a Subscriber can disclose plugin settings, including sensitive API keys. Updating the plugin to version 1.5.5 or later is recommended.
Azərbaycanca: CVE-2026-16594 WordPress üçün WP Directory Kit plaginində 1.5.5 versiyasından əvvəl aşkarlanmış boşluqdur. Avtorizasiya və nonce yoxlaması olmadığı üçün Subscriber kimi autentifikasiya olunmuş istənilən istifadəçi AJAX əməliyyatı vasitəsilə plagin parametrlərini, o cümlədən həssas API açarlarını oxuya bilir. Plagini ən azı 1.5.5 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the WP Directory Kit plugin are affected by CVE-2026-16594?
This vulnerability affects all versions of the WP Directory Kit plugin before version 1.5.5.
What level of permissions does an attacker need to exploit CVE-2026-16594?
The attacker needs to be any authenticated user, such as a Subscriber.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.