Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 10 Aug 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Mon, 10 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Sat, 08 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpdirectorykit Wpdirectorykit wp Directory Kit |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpdirectorykit Wpdirectorykit wp Directory Kit |
Sat, 08 Aug 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 CWE-284 |
Sat, 08 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the WP Directory Kit WordPress plugin before 1.5.5 settings including sensitive API keys and secrets. | |
| Title | WP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key Disclosure | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-10T19:42:00.300Z
Reserved: 2026-07-22T13:47:41.225Z
Link: CVE-2026-16594
Updated: 2026-08-10T19:41:56.405Z
Status : Received
Published: 2026-08-08T07:17:10.910
Modified: 2026-08-10T20:17:27.973
Link: CVE-2026-16594
No data.
OpenCVE Enrichment
Updated: 2026-08-10T23:30:07Z