Description
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpublished listings belonging to other users.
Published: 2026-08-08
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Directory Kit plugin version 1.5.5 and earlier contains a weakness in one of its authenticated AJAX actions. The action fails to enforce authorization or nonce verification, allowing any authenticated user – even a low‑privilege Subscriber – to retrieve the site’s full user list and any listings that have been marked as unpublished. This enables an attacker to gain sensitive information about site membership and developmental content without the knowledge of site administrators. The flaw manifests as an information disclosure vulnerability tied to improper authorization checks.

Affected Systems

WordPress sites that use the WP Directory Kit plugin with a version earlier than 1.5.5 will be vulnerable. The plugin is identified by the vendor/product string Unknown:WP Directory Kit. No specific affected WordPress core or PHP version is listed, so the risk applies to any installation where this plugin is active and a user is logged in.

Risk and Exploitability

The vulnerability’s CVSS score is unspecified but the lack of authentication checks suggests a high severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog, indicating no confirmed public exploits at the time of analysis. The likely attack vector is through a legitimate user account that has been compromised or intentionally used by an attacker; no external input or privilege escalation is necessary beyond authentication. An attacker with any authenticated role can trigger the vulnerable AJAX call to obtain the disclosed data.

Generated by OpenCVE AI on August 8, 2026 at 08:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Directory Kit plugin to version 1.5.5 or later to enforce proper authorization checks.
  • If an immediate plugin update cannot be performed, disable the vulnerable AJAX endpoint or temporarily deactivate the entire plugin until the fix is applied.
  • Reduce or reassign the Subscriber role permissions to limit their ability to trigger the AJAX action, ensuring only users with higher privileges can access listing data.

Generated by OpenCVE AI on August 8, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Sat, 08 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpublished listings belonging to other users.
Title WP Directory Kit < 1.5.5 - Subscriber+ User and Unpublished Listing Disclosure
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-08T06:00:12.661Z

Reserved: 2026-07-22T13:47:43.066Z

Link: CVE-2026-16595

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T08:30:12Z

Weaknesses