CVE-2026-18232
EUVD-2026-7828215.09.2026, 06:16
The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved listings belonging to other users.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.