CVE-2026-18231: WP Directory Kit < 1.5.7 - Unauthenticated User Email Disclosure via select_2_ajax_user
Published Aug 19, 2026
·Updated
The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database rows, allowing unauthenticated attackers to retrieve the usernames and email addresses of users holding the WP Directory Kit WordPress plugin before 1.5.7's own roles.
Affected Software
1 affected component
WordPress WP Directory Kit WordPress plugin<1.5.7
Event History
Aug 19, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated attacker can exploit the affected public AJAX action; no login or authorization is required.
2
What information can be disclosed?
The vulnerable action can return usernames and email addresses for users who hold WP Directory Kit’s own roles.
3
Which installations are affected?
WP Directory Kit versions before 1.5.7 are affected. The issue is in a public AJAX action that lacks an authorization check.