Unrated severityNVD Advisory· Published Sep 15, 2026
CVE-2026-18232
CVE-2026-18232
Description
The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved listings belonging to other users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=1.5.7+ 1 more
- (no CPE)range: <=1.5.7
- (no CPE)range: <=1.5.7
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.