CVE-2026-18231

WP Directory Kit < 1.5.7 - Unauthenticated User Email Disclosure via select_2_ajax_user

The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database rows, allowing unauthenticated attackers to retrieve the usernames and email addresses of users holding the WP Directory Kit WordPress plugin before 1.5.7's own roles.


We have discovered 209 live websites that are affected by CVE-2026-18231.

Run a Free Instant Scan




Affected Software

Product  Wpdirectorykit
Category Wordpress Plugins
Vulnerable Domains209 live websites (100% of Wpdirectorykit install base)
Vulnerable Versions
  • from 0 through 1.5.7
Vulnerable Versions Count16 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Aug 19, 2026
  • Updated - Aug 19, 2026

Credits

  • Erwan LR (WPScan) (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-18231
United States66 websites



Italy21 websites
Germany18 websites
Netherlands8 websites
GB7 websites
India7 websites
Spain7 websites
Cyprus6 websites
France6 websites
Argentina5 websites

Website Distribution by TLD

Number of websites using CVE-2026-18231
.com102 websites
.it15 websites
.org7 websites
.de7 websites
.nl5 websites
.com.br5 websites
.net4 websites
.es4 websites
.com.au3 websites
.eu3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-18231

Top websites that are affected by CVE-2026-18231. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States***,***
***************.org United States***,***
************************.com Germany*,***,***
***************.com United States*,***,***
*****.nl Netherlands*,***,***
************.com United States*,***,***
******.net United States*,***,***
************.com GB*,***,***
*******************.***.au Australia*,***,***
*********.org United States*,***,***
See full domain list

FAQ

CVE-2026-18231 is Exposure of Sensitive Information to an Unauthorized Actor in Wpdirectorykit
A total of 209 websites have been identified as vulnerable to CVE-2026-18231, based on global website indexing conducted by WebTechSurvey.
The Wpdirectorykit is affected by the CVE-2026-18231 vulnerability.
Wpdirectorykit versions up to 1.5.7 are vulnerable to CVE-2026-18231.
CVE-2026-18231 is resolved in version 1.5.7 of Wpdirectorykit.