CVE-2026-16591
WP Directory Kit < 1.5.8 - Listing Admin+ Stored XSS via Category and Location Title and Icon Fields
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category and location fields before outputting them in page attributes, allowing users with a WP Directory Kit WordPress plugin before 1.5.8-specific listing-management role (and without the unfiltered_html capability) to perform Stored Cross-Site Scripting attacks that execute for any visitor of the affected page.
| Vendor | unknown |
| Product | wp directory kit |
| Published | Sep 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp directory kit
Be the first to know when new unknown vulnerabilities affecting unknown wp directory kit are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WP Directory Kit
0 < 1.5.8
References
Credits
Yaswanth Reddy Sunkara WPScan