{"api_version":"1","generated_at":"2026-08-19T11:43:51+00:00","cve":"CVE-2026-18231","urls":{"html":"https://cve.report/CVE-2026-18231","api":"https://cve.report/api/cve/CVE-2026-18231.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-18231","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-18231"},"summary":{"title":"WP Directory Kit < 1.5.7 - Unauthenticated User Email Disclosure via select_2_ajax_user","description":"The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database rows, allowing unauthenticated attackers to retrieve the usernames and email addresses of users holding the WP Directory Kit WordPress plugin before 1.5.7's own roles.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-19 06:17:37","updated_at":"2026-08-19 06:17:37"},"problem_types":["CWE-200 Information Exposure"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/c4508c33-40ac-42c6-aa7e-cf9004d381bd/","name":"https://wpscan.com/vulnerability/c4508c33-40ac-42c6-aa7e-cf9004d381bd/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-18231","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18231","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"WP Directory Kit","version":"affected 1.5.7 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Erwan LR (WPScan)","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"WP Directory Kit","vendor":"Unknown","versions":[{"lessThan":"1.5.7","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Erwan LR (WPScan)"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database rows, allowing unauthenticated attackers to retrieve the usernames and email addresses of users holding the WP Directory Kit WordPress plugin before 1.5.7's own roles."}],"problemTypes":[{"descriptions":[{"description":"CWE-200 Information Exposure","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-19T06:00:18.999Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/c4508c33-40ac-42c6-aa7e-cf9004d381bd/"}],"source":{"discovery":"EXTERNAL"},"title":"WP Directory Kit < 1.5.7 - Unauthenticated User Email Disclosure via select_2_ajax_user","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-18231","datePublished":"2026-08-19T06:00:18.999Z","dateReserved":"2026-07-29T12:18:25.990Z","dateUpdated":"2026-08-19T06:00:18.999Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-19 06:17:37","lastModifiedDate":"2026-08-19 06:17:37","problem_types":["CWE-200 Information Exposure"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"18231","Ordinal":"1","Title":"WP Directory Kit < 1.5.7 - Unauthenticated User Email Disclosure","CVE":"CVE-2026-18231","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"18231","Ordinal":"1","NoteData":"The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database rows, allowing unauthenticated attackers to retrieve the usernames and email addresses of users holding the WP Directory Kit WordPress plugin before 1.5.7's own roles.","Type":"Description","Title":"WP Directory Kit < 1.5.7 - Unauthenticated User Email Disclosure"}]}}}