Wp Directory Kit

WordPress plugin · wp-directory-kit · WordPress.org ↗
1
Critical
5
High
12
Known total
3
Unfixed
Running Wp Directory Kit on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
CRITICAL
CVSS 9.1
WP Directory Kit < 1.5.5 - Unauthenticated SQL Injection via 'field_search' Parameter
CVE.org
>=1.5.4, <1.5.5 v1.5.5 CVE-2026-18473 Aug 9, 2026
HIGH
CVSS 7.2
WP Directory Kit < 1.5.7 - Admin+ SQL Injection via section Parameter
CVE.org
>=0, <1.5.7 v1.5.7 CVE-2026-18653 Aug 16, 2026
HIGH
CVSS 8.1
WP Directory Kit < 1.5.6 - Subscriber+ SQL Injection via section Parameter
CVE.org
>=0, <1.5.6 v1.5.6 CVE-2026-18230 Aug 12, 2026
HIGH
CVSS 8.6
WP Directory Kit < 1.5.6 - Unauthenticated SQL Injection via search_location and search_category
CVE.org
>=0, <1.5.6 v1.5.6 CVE-2026-18474 Aug 12, 2026
HIGH
CVSS 7.7
WP Directory Kit < 1.5.5 - Subscriber+ SQL Injection via data_fields_list Parameter
CVE.org
>=0, <1.5.5 v1.5.5 CVE-2026-16589 Aug 8, 2026
HIGH
CVSS 7.5
WP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key Disclosure
CVE.org
>=0, <1.5.5 v1.5.5 CVE-2026-16594 Aug 8, 2026
MEDIUM
CVSS 6.8
WP Directory Kit <= 1.5.7 - Editor+ SQL Injection via Elementor Category and Location Widget Settings
CVE.org
<=1.5.7 unfixed CVE-2026-16593 Sep 15, 2026
MEDIUM
CVSS 5.3
WP Directory Kit <= 1.5.7 - Unauthenticated Unpublished Listing Disclosure via map_infowindow
CVE.org
<=1.5.7 unfixed CVE-2026-18232 Sep 15, 2026
MEDIUM
CVSS 5.3
WP Directory Kit < 1.5.7 - Unauthenticated User Email Disclosure via select_2_ajax_user
CVE.org
>=0, <1.5.7 v1.5.7 CVE-2026-18231 Aug 19, 2026
MEDIUM
CVSS 6.5
WP Directory Kit < 1.5.5 - Subscriber+ Contact Message and User Data Disclosure
CVE.org
>=0, <1.5.5 v1.5.5 CVE-2026-16590 Aug 8, 2026
MEDIUM
CVSS 6.5
WP Directory Kit < 1.5.5 - Subscriber+ User and Unpublished Listing Disclosure
CVE.org
>=0, <1.5.5 v1.5.5 CVE-2026-16595 Aug 8, 2026
LOW
CVSS 2.7
WP Directory Kit <= 1.5.7 - Contributor+ Non-Public Listing Field Disclosure via Shortcodes
CVE.org
<=1.5.7 unfixed CVE-2026-16592 Sep 15, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.