Impact
Unauthenticated Broken Access Control exists in WP Directory Kit plugin version 1.5.0 and earlier. The flaw allows any external user to bypass authentication checks and gain access to administrative or protected resources within the plugin. This could lead to exposure or unauthorized modification of directory listings, user data, or site configuration, and potentially serve as a foothold for further compromise.
Affected Systems
WordPress sites running the WP Directory Kit plugin (Wp Directory Kit) at version 1.5.0 or earlier are affected. All installations that have not been updated beyond 1.5.0 fall under the vulnerability.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, but the EPSS score of less than 1% suggests exploitation is unlikely at present. The flaw is not listed in the CISA KEV catalog. The likely attack vector is through the website’s HTTP interface, where an unauthenticated attacker can submit crafted requests to trigger the broken access control. No specific software prerequisites are mentioned beyond the presence of the vulnerable plugin.
OpenCVE Enrichment