---
id: CVE-2026-16591
title: >-
  The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and
  escape some of its category and location fields before outputting them in page
  attributes, allowing users with a WP Directory Kit WordPress plugin before
  1.5.8-spec…
summary: >-
  The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and
  escape some of its category and location fields before outputting them in page
  attributes, allowing users with a WP Directory Kit WordPress plugin before
  1.5.8-spec…
severity: none
cwe:
  - CWE-79
product: WP Directory Kit
affected:
  - wp_directory_kit < 1.5.8
published: '2026-09-26'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T07:17:01.937'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16591'
references:
  - url: 'https://wpscan.com/vulnerability/7b5600f1-1024-4329-97de-6347420e46c1/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-26T06:27:03.682Z'
---

## Overview

The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category and location fields before outputting them in page attributes, allowing users with a WP Directory Kit WordPress plugin before 1.5.8-specific listing-management role (and without the unfiltered_html capability) to perform Stored Cross-Site Scripting attacks that execute for any visitor of the affected page.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
