SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-18231

MEDIUM · CVSS 5.3 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The WP Directory Kit plugin for WordPress versions prior to 1.5.7 is vulnerable due to a lack of authorization checks on a public AJAX action, which allows unauthenticated attackers to access unfiltered database rows. This exposure enables attackers to retrieve sensitive user information, including usernames and email addresses of users with roles in the plugin. WordPress site administrators using this plugin should prioritize updating to version 1.5.7 or later to mitigate the risk of unauthorized data access.

CVE
CVE-2026-18231
Severity
MEDIUM
CVSS
5.3
EPSS
0.25%
WordPress

Original NVD Description

The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database rows, allowing unauthenticated attackers to retrieve the usernames and email addresses of users holding the WP Directory Kit WordPress plugin before 1.5.7's own roles.