Impact
The WP Directory Kit WordPress plugin exposes a public AJAX endpoint that does not perform an authorization check and returns raw database rows. An unauthenticated attacker can call this endpoint and retrieve the usernames and email addresses of all users that are members of the WP Directory Kit plugin’s own roles, thereby leaking personal contact information. This vulnerability is a breach of confidentiality and is classified as CWE‑200.
Affected Systems
WordPress sites running WP Directory Kit versions earlier than 1.5.7 are affected. No other products or versions are listed as vulnerable by the CNA.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of less than 1 % suggests that exploitation is currently unlikely to be widespread. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw simply by sending unauthenticated requests to the AJAX endpoint; no special conditions or privileges are required.
OpenCVE Enrichment