Description
The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved listings belonging to other users.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated disclosure of unpublished listings
Action: Apply patch
AI Analysis

Impact

The WP Directory Kit plugin, up to version 1.5.7, fails to verify the status or owner of a listing before returning its content via the map_infowindow AJAX action. This flaw allows any visitor without authentication to retrieve draft or unapproved listings that belong to other users, exposing sensitive information that should remain private.

Affected Systems

WordPress sites that have installed WP Directory Kit 1.5.7 or earlier are affected. Site administrators should verify whether their installations still use the vulnerable plugin version; any deployment of version 1.5.7 or below is subject to this vulnerability.

Risk and Exploitability

The flaw carries a CVSS score of 5.3, indicating moderate severity. EPSS is less than 1%, suggesting a low likelihood of widespread exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Since it is an unauthenticated information disclosure, an attacker only needs to send a crafted AJAX request to the map_infowindow endpoint; no additional credentials or privileges are required.

Generated by OpenCVE AI on September 20, 2026 at 17:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Directory Kit to the latest version that includes the same fix or a newer release that replaces the vulnerable AJAX action, ensuring any updates that perform a status/ownership check on listings are applied immediately.
  • If an upgrade is not possible, block or remove the map_infowindow endpoint from public access by editing the plugin files or using a security plugin that restricts access to AJAX actions only to authenticated users.
  • Enforce authentication and role-based permissions for all listing-related AJAX calls in the plugin’s code, guaranteeing that only owners or administrators can request unpublished or draft listings.

Generated by OpenCVE AI on September 20, 2026 at 17:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved listings belonging to other users.
Title WP Directory Kit <= 1.5.7 - Unauthenticated Unpublished Listing Disclosure via map_infowindow
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-15T14:24:45.146Z

Reserved: 2026-07-29T12:19:04.736Z

Link: CVE-2026-18232

cve-icon Vulnrichment

Updated: 2026-09-15T14:24:26.232Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T06:16:57.953

Modified: 2026-09-16T20:25:29.240

Link: CVE-2026-18232

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:00:14Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor