The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved listings belonging to other users.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 06:16
Updated : 2026-09-16 20:25
NVD link : CVE-2026-18232
Mitre link : CVE-2026-18232
CVE.ORG link : CVE-2026-18232
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
