
CVE-2026-16594 The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated… https://www.cve.org/CVERecord?id=CVE-2026-16594
Post summary
The text announces a missing authorization/nonce check in the WP Directory Kit plugin prior to version 1.5.5, revealing a flaw in an authenticated AJAX action. No PoC, exploit, or patch details are provided.

