{"id":"CVE-2026-16590","title":"The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to retrieve stored contact messages and asso…","summary":"The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to retrieve stored contact messages and asso…","severity":"none","published":"2026-08-08","updated":"2026-08-08","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-16590","references":[{"url":"https://wpscan.com/vulnerability/ddf13b08-4ee2-46a1-929c-1f435e9e49d4/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00219,"epssPercentile":0.12617,"ingestedAt":"2026-08-09T03:32:40.496Z","slug":"CVE-2026-16590","body":"## Overview\n\nThe WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to retrieve stored contact messages and associated user data belonging to other users.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}