Executive brief
WP Directory Kit is a WordPress plugin used to create and manage business directories on WordPress sites. The plugin improperly validates user permissions on an AJAX endpoint, allowing any logged-in user—even those with minimal privileges (Subscriber role)—to retrieve sensitive plugin configuration including API keys for services like reCAPTCHA and Google Maps. An attacker with a basic user account could extract these secrets and use them to compromise the directory site or associated services.
Technical details
The vulnerability is an authorization bypass caused by missing permission and nonce validation in an authenticated AJAX action handler (wdk_admin_action). An attacker with any authenticated user account (e.g., Subscriber role) can POST to admin-ajax.php with specific parameters to trigger the settings-page rendering without proper authorization checks. The vulnerable code falls through to a display branch that renders plugin settings containing sensitive data (API keys, secrets) in plain HTML. This is exploitable because WordPress authentication alone does not enforce role-based access control; the plugin must explicitly check capabilities. A patch is available in version 1.5.5 and later.
Affected products
- WP Directory Kit WP Directory Kit before 1.5.5
Timeline
- 2026-08-03: disclosed
- 2026-08-08: patched