The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database rows, allowing unauthenticated attackers to retrieve the usernames and email addresses of users holding the WP Directory Kit WordPress plugin before 1.5.7's own roles.
History

Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 19 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database rows, allowing unauthenticated attackers to retrieve the usernames and email addresses of users holding the WP Directory Kit WordPress plugin before 1.5.7's own roles.
Title WP Directory Kit < 1.5.7 - Unauthenticated User Email Disclosure via select_2_ajax_user
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-08-19T06:00:18.999Z

Updated: 2026-08-19T16:10:32.478Z

Reserved: 2026-07-29T12:18:25.990Z

Link: CVE-2026-18231

cve-icon Vulnrichment

Updated: 2026-08-19T16:01:49.502Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T06:17:37.450

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-18231

cve-icon Redhat

No data.