Impact
The WP Directory Kit WordPress plugin, versions up to 1.5.7, fails to enforce authorization or visibility checks in one of its shortcodes. This flaw allows users with a Contributor role or higher to retrieve non‑public content from listings belonging to other users, including password‑protected and hidden fields. The vulnerability is an information‑disclosure flaw with a CVSS score of 2.7.
Affected Systems
WP Directory Kit versions 1.5.7 and earlier are affected. The vulnerability applies to the plugin as a whole; specific sub‑versions beyond 1.5.7 are not impacted.
Risk and Exploitability
The EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The exploit requires a Contributor‑level or higher account already authenticated to the site; a short‑code providing unrestricted access is the likely vector. Although the impact is limited to data disclosure rather than code execution, the risk remains moderate due to the ease of accessing sensitive information.
OpenCVE Enrichment