← back
CVE-2026-16591highCWE-79

WP Directory Kit < 1.5.8 - Listing Admin+ Stored XSS via Category and Location Title and Icon Fields

41Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 7.2epss 0.2%
exploitation probability
0.2%top 96% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category and location fields before outputting them in page attributes, allowing users with a WP Directory Kit WordPress plugin before 1.5.8-specific listing-management role (and without the unfiltered_html capability) to perform Stored Cross-Site Scripting attacks that execute for any visitor of the affected page.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.