CVE-2026-18232: WP Directory Kit <= 1.5.7 - Unauthenticated Unpublished Listing Disclosure via map_infowindow
Published Sep 15, 2026
·Updated
The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved listings belonging to other users.
Affected Software
1 affected component
WordPress plugin "WP Directory Kit"<=1.5.7
Event History
Sep 15, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated attacker can exploit the affected public AJAX action; no WordPress account is required.
2
What information can be exposed?
The issue can disclose draft and unapproved listings that belong to other users.
3
Which installations are affected?
WP Directory Kit versions through 1.5.7 are affected. The issue is in a public AJAX action, so sites exposing the plugin's map_infowindow functionality are relevant to triage.