{"id":"CVE-2026-16594","title":"The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the WP Directory Kit WordPress p…","summary":"The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the WP Directory Kit WordPress p…","severity":"none","published":"2026-08-08","updated":"2026-08-08","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-16594","references":[{"url":"https://wpscan.com/vulnerability/d055d385-7e8a-4179-aa21-f07e240fd181/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00245,"epssPercentile":0.16014,"ingestedAt":"2026-08-09T03:32:40.529Z","slug":"CVE-2026-16594","body":"## Overview\n\nThe WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the WP Directory Kit WordPress plugin before 1.5.5 settings including sensitive API keys and secrets.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}