Executive brief
The WP Directory Kit WordPress plugin fails to properly sanitize category and location field inputs before displaying them on web pages. An attacker with the listing-management role can inject malicious scripts that execute in the browsers of all website visitors viewing affected pages, potentially stealing credentials or compromising site security.
Technical details
The plugin does not sanitize and escape category and location title and icon fields before outputting them in HTML page attributes, enabling stored XSS. Users with the plugin-specific listing-management role (lacking unfiltered_html capability) can inject arbitrary JavaScript that persists in the database and executes for any visitor. The vulnerability is fixed in version 1.5.8.
Affected products
- WP Directory Kit WP Directory Kit before 1.5.8
Timeline
- 2026-09-24: disclosed
- 2026-09-24: patched: Fixed in version 1.5.8