CVE-2026-16594: WP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key Disclosure
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the WP Directory Kit WordPress plugin before 1.5.5 settings including sensitive API keys and secrets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16594?
CVE-2026-16594 has a risk score of 57, indicating it's a medium severity vulnerability.
How do I fix CVE-2026-16594?
Updating the WP Directory Kit WordPress plugin to version 1.5.5 or newer will resolve CVE-2026-16594.
What does CVE-2026-16594 affect?
CVE-2026-16594 affects versions of the WP Directory Kit WordPress plugin earlier than 1.5.5.
What type of vulnerability is CVE-2026-16594?
CVE-2026-16594 is classified as an information disclosure vulnerability.
Who is at risk from CVE-2026-16594?
Any authenticated user with Subscriber level access can exploit CVE-2026-16594 to disclose sensitive information.