CVE-2026-18232

The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved listings belonging to other users.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-15 06:16

Updated : 2026-09-16 20:25


NVD link : CVE-2026-18232

Mitre link : CVE-2026-18232

CVE.ORG link : CVE-2026-18232


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor