Impact
The vulnerability resides in the WP Directory Kit WordPress plugin before version 1.5.5. It permits any authenticated user, including those with the Subscriber role, to invoke an AJAX action that lacks proper authorization or nonce checks. This oversight allows the requesting user to read contact messages stored by the plugin and to obtain user data belonging to other users. The primary impact is the exposure of sensitive information that should be protected by access controls, potentially compromising user privacy and confidentiality.
Affected Systems
The affected product is the WP Directory Kit WordPress plugin, any installation running a version earlier than 1.5.5. No host or server details are provided, but the issue applies to every site that has this plugin activated and has any authenticated users.
Risk and Exploitability
An attacker who is able to authenticate to the site with any role that can access WordPress, even a Subscriber, can exploit this flaw. Because the attacker only needs to be logged in, the attack vector is relatively easy: gain or compromise a user account. The CVSS base score is inherently high for information disclosure, and the lack of exploitation data in EPSS or KEV indicates the flaw is not widely exploited yet, but the risk remains significant for any site relying on this plugin. Fixing the plug‑in upgrade path removes the vulnerability; no public exploit code is known at present.
OpenCVE Enrichment