{"id":"CVE-2026-16595","title":"The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpubli…","summary":"The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpubli…","severity":"none","published":"2026-08-08","updated":"2026-08-08","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-16595","references":[{"url":"https://wpscan.com/vulnerability/e960f5b2-18e9-436b-8828-6a105c7f9dd5/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00219,"epssPercentile":0.126,"ingestedAt":"2026-08-09T03:32:40.561Z","slug":"CVE-2026-16595","body":"## Overview\n\nThe WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpublished listings belonging to other users.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}