CVE-2026-16590Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to retrieve stored contact messages and associated user data belonging to other users.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-08: 3Technical Details · 2026-08-08: 308-08
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-16590 The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated… https://www.cve.org/CVERecord?id=CVE-2026-16590

    Post summary

    The post discloses that versions of WP Directory Kit before 1.5.5 lack proper authorization checks on an authenticated AJAX action, potentially exposing a privilege escalation flaw for authenticated users.

    00001936
    57.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-16590 The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated… https://www.cve.org/CVERecord?id=CVE-2026-16590 ----- Traducción: CVE-2026-16590 El … http://infoflow.cloud`

    Post summary

    The passage announces CVE-2026-16590, identifies an authorization flaw in WP Directory Kit, but provides no PoC, exploit, or remediation details.

    00000103
    98 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    📩 WordPress flaw exposes private contact messages CVE-2026-16590 Another WP Directory Kit <1.5.5 vulnerability allows low-privileged authenticated users to retrieve stored contact messages and associated user information belonging to others. 🔎 Source: Rapid7 / WPScan / MITRE #WordPress #Privacy #CVE #WebSecurity #CyberSecurity

    Post summary

    The tweet announces a newly identified WordPress Directory Kit vulnerability (CVE‑2026‑16590) that lets low‑privileged authenticated users access other users’ private contact messages and user data, with no PoC, exploit evidence, or patch information disclosed.

    00000118
    34 followersView on X

Explore more