VYPR

Wp Directory Kit

by WordPress

Source repositories

CVEs (33)

  • CVE-2026-28001CriAug 13, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.

  • CVE-2026-42672CriJun 1, 2026
    risk 0.60cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.1.

  • CVE-2026-39531CriMay 21, 2026
    risk 0.60cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.0.

  • CVE-2026-18473CriAug 9, 2026
    risk 0.59cvss 9.1epss 0.00

    The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

  • CVE-2025-13390CriDec 3, 2025
    risk 0.58cvss 10.0epss 0.05

    The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication algorithm in the "wdk_generate_auto_login_link" function. This is due to the feature using a…

  • CVE-2023-2278CriJun 13, 2023
    risk 0.57cvss 9.8epss 0.02

    The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 via the 'wdk_public_action' function. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any…

  • CVE-2026-18474HigAug 12, 2026
    risk 0.56cvss 8.6epss 0.00

    The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when a non-default search field type is configured.

  • CVE-2026-18230HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks an authorization check, allowing any authenticated user such as a Subscriber to perform SQL…

  • CVE-2026-16589HigAug 8, 2026
    risk 0.50cvss 7.7epss 0.00

    The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks authorization and nonce checks, allowing any authenticated user such as a Subscriber to…

  • CVE-2024-3217HigApr 5, 2024
    risk 0.50cvss 8.8epss 0.02

    The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' parameters in all versions up to, and including, 1.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  • CVE-2026-27538HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.

  • CVE-2026-16594HigAug 8, 2026
    risk 0.49cvss 7.5epss 0.00

    The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the WP Directory Kit WordPress plugin before 1.5.5 settings including…

  • CVE-2026-39534HigJun 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions.

  • CVE-2025-13089HigDec 13, 2025
    risk 0.49cvss 7.5epss 0.00

    The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'hide_fields' and the 'attr_search' parameter in all versions up to, and including, 1.4.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  • CVE-2025-13138HigNov 21, 2025
    risk 0.49cvss 7.5epss 0.02

    The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'columns_search' parameter of the select_2_ajax() function in all versions up to, and including, 1.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

  • CVE-2026-18653HigAug 16, 2026
    risk 0.47cvss 7.2epss 0.00

    The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrators to perform SQL injection attacks. On a multisite installation this lets an administrator of a single site read data belonging…

  • CVE-2024-37487HigJul 21, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wpdirectorykit.Com WP Directory Kit allows Reflected XSS.This issue affects WP Directory Kit: from n/a through 1.3.5.

  • CVE-2024-29774HigMar 27, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpDirectoryKit WP Directory Kit allows Reflected XSS.This issue affects WP Directory Kit: from n/a through 1.2.9.

  • CVE-2026-16595MedAug 8, 2026
    risk 0.42cvss 6.5epss 0.00

    The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpublished listings belonging to other users.

  • CVE-2026-16590MedAug 8, 2026
    risk 0.42cvss 6.5epss 0.00

    The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to retrieve stored contact messages and associated user data belonging to other users.

Page 1 of 2