What is CVE-2026-18231?
CVE-2026-18231 is a vulnerability in the WP Directory Kit WordPress plugin for versions before 1.5.7, where a public AJAX action lacks authorization checks. This allows unauthenticated attackers to retrieve usernames and email addresses of plugin users by querying unfiltered database rows. Updating to version 1.5.7 is required to address this issue.
Azərbaycanca: CVE-2026-18231, WP Directory Kit WordPress plaginin 1.5.7-dən əvvəlki versiyalarında aşkarlanmış bir zəiflikdir. Plagin ictimai AJAX əməliyyatı üzərində avtorizasiya yoxlaması aparmadığı üçün autentifikasiya olunmamış hücumçulara plugin istifadəçilərinin istifadəçi adı və e-poçt ünvanlarını əldə etməyə imkan verir. Plaginin ən son 1.5.7 versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which plugin is affected by CVE-2026-18231?
CVE-2026-18231 affects the WP Directory Kit WordPress plugin for versions prior to 1.5.7.
What information can an unauthenticated attacker obtain via this vulnerability?
An unauthenticated attacker can retrieve usernames and email addresses of plugin users.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.