Impact
The WP Directory Kit plugin version 1.5.5 and earlier contains a weakness in one of its authenticated AJAX actions. The action fails to enforce authorization or nonce verification, allowing any authenticated user – even a low‑privilege Subscriber – to retrieve the site’s full user list and any listings that have been marked as unpublished. This enables an attacker to gain sensitive information about site membership and developmental content without the knowledge of site administrators. The flaw manifests as an information disclosure vulnerability tied to improper authorization checks.
Affected Systems
WordPress sites that use the WP Directory Kit plugin with a version earlier than 1.5.5 will be vulnerable. The plugin is identified by the vendor/product string Unknown:WP Directory Kit. No specific affected WordPress core or PHP version is listed, so the risk applies to any installation where this plugin is active and a user is logged in.
Risk and Exploitability
The vulnerability’s CVSS score is unspecified but the lack of authentication checks suggests a high severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog, indicating no confirmed public exploits at the time of analysis. The likely attack vector is through a legitimate user account that has been compromised or intentionally used by an attacker; no external input or privilege escalation is necessary beyond authentication. An attacker with any authenticated role can trigger the vulnerable AJAX call to obtain the disclosed data.
OpenCVE Enrichment