Description
The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role as low as Contributor to disclose non-public listing content, including password-protected and hidden fields, belonging to other users.
Published: 2026-09-15
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure: non‑public listing content can be accessed by Users with Contributor role.
Action: Assess Impact
AI Analysis

Impact

The WP Directory Kit WordPress plugin, versions up to 1.5.7, fails to enforce authorization or visibility checks in one of its shortcodes. This flaw allows users with a Contributor role or higher to retrieve non‑public content from listings belonging to other users, including password‑protected and hidden fields. The vulnerability is an information‑disclosure flaw with a CVSS score of 2.7.

Affected Systems

WP Directory Kit versions 1.5.7 and earlier are affected. The vulnerability applies to the plugin as a whole; specific sub‑versions beyond 1.5.7 are not impacted.

Risk and Exploitability

The EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The exploit requires a Contributor‑level or higher account already authenticated to the site; a short‑code providing unrestricted access is the likely vector. Although the impact is limited to data disclosure rather than code execution, the risk remains moderate due to the ease of accessing sensitive information.

Generated by OpenCVE AI on September 20, 2026 at 18:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest patch or upgrade WP Directory Kit to the most recent released version; if no newer version exists, reach out to the vendor for a fix that addresses information disclosure (CWE‑200).
  • Restrict the use of the shortcode that exposes listing data to users with Administrator privileges only; disable or restrict it for Contributor level and lower.
  • ensure that only authorized users can access non‑public listing content. This mitigates CWE‑200.

Generated by OpenCVE AI on September 20, 2026 at 18:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role as low as Contributor to disclose non-public listing content, including password-protected and hidden fields, belonging to other users.
Title WP Directory Kit <= 1.5.7 - Contributor+ Non-Public Listing Field Disclosure via Shortcodes
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-15T14:25:13.079Z

Reserved: 2026-07-22T13:47:36.774Z

Link: CVE-2026-16592

cve-icon Vulnrichment

Updated: 2026-09-15T14:25:04.636Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T06:16:57.127

Modified: 2026-09-16T20:25:29.240

Link: CVE-2026-16592

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:15:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor