What is CVE-2026-16595?
CVE-2026-16595: A vulnerability in the WP Directory Kit WordPress plugin (before version 1.5.5) involves missing authorization and nonce checks on an authenticated AJAX action, allowing low-privileged users like Subscribers to expose the site's user list and unpublished listings of other users. Immediate update to version 1.5.5 or higher is recommended.
Azərbaycanca: CVE-2026-16595: WP Directory Kit WordPress plaginində müəyyən edilmiş boşluq, <1.5.5 versiyalarında autentifikasiya və nonce yoxlanışının olmaması səbəbindən aşağı səlahiyyətli istifadəçilərə (məsələn, Abunəçi) saytın istifadəçi siyahısı və digər istifadəçilərə aid dərc olunmamış elanları əldə etməyə imkan verir. Təsirə məruz qalan sistemlərin təcili olaraq 1.5.5 və ya daha yüksək versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the WP Directory Kit plugin are affected by CVE-2026-16595?
Versions of the WP Directory Kit plugin before 1.5.5 are affected by this vulnerability.
What data can an authenticated Subscriber access by exploiting CVE-2026-16595?
An authenticated Subscriber can expose the site's user list and unpublished listings of other users.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.