WP Directory Kit

22 known CVEs 2K+ active installs

Scan My Site Free

UNKNOWN: 22
Known Vulnerabilities 22
CVE-2025-13920 UNKNOWN EPSS 0.5%
Published 2026-01-24 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action AJAX handler. This makes it possible for
CVE-2025-13089 UNKNOWN EPSS 0.3%
Published 2025-12-13 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'hide_fields' and the 'attr_search' parameter in all versions up to, and including, 1.4.7 due to insufficient escaping
CVE-2025-13390 UNKNOWN EPSS 0.9%
Published 2025-12-03 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication algorithm in the "wdk
CVE-2025-13090 UNKNOWN EPSS 0.2%
Published 2025-12-02 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up to, and including, 1.4.6 due to insufficient escaping on the user supplied parame
CVE-2025-13525 UNKNOWN EPSS 0.2%
Published 2025-11-27 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order_by' parameter in all versions up to, and including, 1.4.5 due to insufficient input sanitizatio
CVE-2025-13138 UNKNOWN EPSS 0.7%
Published 2025-11-21 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'columns_search' parameter of the select_2_ajax() function in all versions up to, and including, 1.4.3 due to insuffici
CVE-2023-41875 UNKNOWN EPSS 0.5%
Published 2024-12-13 · Affected: *
Missing Authorization vulnerability in wpdirectorykit.com WP Directory Kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Directory Kit: from n/a through
CVE-2023-41875 UNKNOWN EPSS 0.5%
Published 2024-12-13 · Affected: *
Missing Authorization vulnerability in wpdirectorykit.com WP Directory Kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Directory Kit: from n/a through
CVE-2024-3217 UNKNOWN EPSS 0.8%
Published 2024-04-05 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' parameters in all versions up to, and including, 1.3.0 due to insufficient escapin
CVE-2024-3217 UNKNOWN EPSS 0.8%
Published 2024-04-05 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' parameters in all versions up to, and including, 1.3.0 due to insufficient escapin
CVE-2023-2279 UNKNOWN EPSS 0.2%
Published 2023-08-31 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the 'admin_page_d
CVE-2023-2279 UNKNOWN EPSS 0.2%
Published 2023-08-31 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the 'admin_page_d
CVE-2023-2351 UNKNOWN EPSS 0.5%
Published 2023-06-13 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'ajax_admin' function in versions up to, and incl
CVE-2023-2351 UNKNOWN EPSS 0.5%
Published 2023-06-13 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'ajax_admin' function in versions up to, and incl
CVE-2023-2278 UNKNOWN EPSS 0.8%
Published 2023-06-13 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 via the 'wdk_public_action' function. This allows unauthenticated attackers to i
CVE-2023-2278 UNKNOWN EPSS 0.8%
Published 2023-06-13 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 via the 'wdk_public_action' function. This allows unauthenticated attackers to i
CVE-2023-2277 UNKNOWN EPSS 0.3%
Published 2023-06-13 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.9. This is due to missing or incorrect nonce validation on the 'insert' func
CVE-2023-2277 UNKNOWN EPSS 0.3%
Published 2023-06-13 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.9. This is due to missing or incorrect nonce validation on the 'insert' func
CVE-2023-2280 UNKNOWN EPSS 0.5%
Published 2023-06-09 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'ajax_public' function in versions up to, and inc
CVE-2023-2280 UNKNOWN EPSS 0.5%
Published 2023-06-09 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'ajax_public' function in versions up to, and inc
CVE-2023-2835 UNKNOWN EPSS 0.5%
Published 2023-06-02 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in versions up to, and including, 1.2.3 due to insufficient input sanitization and
CVE-2023-2835 UNKNOWN EPSS 0.5%
Published 2023-06-02 · Affected: *
The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in versions up to, and including, 1.2.3 due to insufficient input sanitization and

Is WP Directory Kit running on your site?

A free scan detects your plugins and flags any that match these CVEs.

Scan My Site Free