Executive brief
WP Directory Kit is a WordPress plugin used to create and manage directory listings on websites. A security flaw in versions 1.5.0 and earlier allows unauthorized individuals to bypass access controls, potentially leading to the exposure of sensitive data. This could allow attackers to view information they are not permitted to see, compromising the privacy of the directory's users or site operations.
Technical details
A broken access control vulnerability exists in the WP Directory Kit plugin for WordPress due to missing authorization checks (CWE-862). The flaw allows an unauthenticated remote attacker to bypass intended access restrictions by interacting with vulnerable functions that lack proper permission or nonce validation. According to the CVSS vector, this vulnerability primarily impacts confidentiality, allowing an attacker to retrieve sensitive information without prior authentication. The issue is resolved in version 1.5.1.
Affected products
- WP Directory Kit WP Directory Kit <= 1.5.0
Timeline
- 2026-02-18: other: Reported by researcher Martín Martín
- 2026-04-08: disclosed: Initial disclosure by Patchstack
- 2026-06-15: advisory: NVD publication date