
CVE-2026-16590 The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated… https://www.cve.org/CVERecord?id=CVE-2026-16590
Post summary
The post discloses that versions of WP Directory Kit before 1.5.5 lack proper authorization checks on an authenticated AJAX action, potentially exposing a privilege escalation flaw for authenticated users.


