CVE-2026-16595Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpublished listings belonging to other users.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-08: 3Technical Details · 2026-08-08: 308-08
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-16595 The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated… https://www.cve.org/CVERecord?id=CVE-2026-16595 ----- Traducción: CVE-2026-16595 El … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑16595, describing missing authorization and nonce checks in WP Directory Kit WordPress plugin that could allow authenticated users to perform unauthorized AJAX actions.

    00000103
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-16595 The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated… https://www.cve.org/CVERecord?id=CVE-2026-16595

    Post summary

    The text reports a new authorization bypass vulnerability in WP Directory Kit before v1.5.5, with no evidence of exploitation, PoC, or patch details.

    000001.9K
    57.9K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    👥 WordPress plugin can expose user lists + unpublished content CVE-2026-16595 affects WP Directory Kit <1.5.5. A Subscriber-level account can abuse an improperly protected AJAX action to access the site's user list and unpublished listings belonging to other users. 🔎 Source: Rapid7 / WPScan / MITRE #WordPress #DataExposure #CVE #CyberSecurity

    Post summary

    The post discloses CVE-2026-16595, detailing how an abused AJAX action in WP Directory Kit can expose user lists and unpublished content, but offers no PoC, exploit, or patch information.

    00000150
    34 followersView on X

Explore more