CVE-2026-16591: CWE-79 Cross-Site Scripting (XSS) in WP Directory Kit
The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category and location fields before outputting them in page attributes, allowing users with a WP Directory Kit WordPress plugin before 1.5.8-specific listing-management role (and without the unfiltered_html capability) to perform Stored Cross-Site Scripting attacks that execute for any visitor of the affected page.
AI Analysis
Technical Summary
The WP Directory Kit WordPress plugin prior to version 1.5.8 contains a stored XSS vulnerability (CWE-79) due to improper sanitization and escaping of category and location fields. Users assigned a WP Directory Kit-specific listing-management role, even without unfiltered_html capability, can inject malicious scripts into these fields. These scripts execute in the context of any visitor viewing the affected page, potentially leading to session hijacking, defacement, or other script-based attacks.
Potential Impact
An attacker with the listing-management role in WP Directory Kit can perform stored XSS attacks that execute arbitrary JavaScript in the browsers of visitors to the affected pages. This can lead to theft of cookies, session tokens, or other sensitive information, as well as unauthorized actions performed on behalf of the visitor. The vulnerability affects all visitors to the compromised pages, increasing the risk of widespread impact.
Mitigation Recommendations
Upgrade the WP Directory Kit plugin to version 1.5.8 or later, where this vulnerability is fixed. Since the plugin is not a cloud service and no official patch link is provided in the data, users should verify the availability of the fixed version from the official plugin repository or vendor site. Patch status is not yet confirmed in the provided data — check the vendor advisory for current remediation guidance.
CVE-2026-16591: CWE-79 Cross-Site Scripting (XSS) in WP Directory Kit
Description
The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category and location fields before outputting them in page attributes, allowing users with a WP Directory Kit WordPress plugin before 1.5.8-specific listing-management role (and without the unfiltered_html capability) to perform Stored Cross-Site Scripting attacks that execute for any visitor of the affected page.
CVSS v3.1
Score 7.2high
Affected software
WP Directory Kit
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The WP Directory Kit WordPress plugin prior to version 1.5.8 contains a stored XSS vulnerability (CWE-79) due to improper sanitization and escaping of category and location fields. Users assigned a WP Directory Kit-specific listing-management role, even without unfiltered_html capability, can inject malicious scripts into these fields. These scripts execute in the context of any visitor viewing the affected page, potentially leading to session hijacking, defacement, or other script-based attacks.
Potential Impact
An attacker with the listing-management role in WP Directory Kit can perform stored XSS attacks that execute arbitrary JavaScript in the browsers of visitors to the affected pages. This can lead to theft of cookies, session tokens, or other sensitive information, as well as unauthorized actions performed on behalf of the visitor. The vulnerability affects all visitors to the compromised pages, increasing the risk of widespread impact.
Mitigation Recommendations
Upgrade the WP Directory Kit plugin to version 1.5.8 or later, where this vulnerability is fixed. Since the plugin is not a cloud service and no official patch link is provided in the data, users should verify the availability of the fixed version from the official plugin repository or vendor site. Patch status is not yet confirmed in the provided data — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-22T13:47:34.868Z
- State
- PUBLISHED
Threat ID: 6ab7672cf7a7c54106f7c88c
Added to database: 09/26/2026, 06:33:16 UTC
Last enriched: 09/26/2026, 06:48:21 UTC
Last updated: 09/27/2026, 04:31:16 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.