Impact
The vulnerability resides in the WP Directory Kit WordPress plugin before version 1.5.5. It permits any authenticated user, including those with the Subscriber role, to invoke an AJAX action that lacks proper authorization or nonce checks. This oversight allows the requesting user to read contact messages stored by the plugin and to obtain user data belonging to other users. The primary impact is the exposure of sensitive information that should be protected by access controls, potentially compromising user privacy and confidentiality.
Affected Systems
The affected product is the WP Directory Kit WordPress plugin, any installation running a version earlier than 1.5.5. No host or server details are provided, but the issue applies to every site that has this plugin activated and has any authenticated users.
Risk and Exploitability
An attacker who is able to authenticate to the site with any role that can access WordPress, even a Subscriber, can exploit this flaw. Because the attacker only needs to be logged in, the attack vector is relatively easy: gain or compromise a user account. The CVSS score of 6.5 indicates medium severity for information disclosure, while the EPSS score of < 1% and the absence from the CISA KEV catalog imply a low probability of exploitation; however, the vulnerability still poses a significant privacy risk to any affected site. Fixing the plug‑in upgrade path removes the vulnerability; no public exploit code is known at present.
OpenCVE Enrichment